Windows: Local user account creation via net.exe or net1.exe
Alerts on net.exe/net1.exe launching with "user" and "add" to create local accounts on Windows.
FreeUnreviewedSigmamediumv1
windows-local-user-account-creation-via-net-exe-or-net1-exe-cd219ff3
title: "Windows: Local user account creation via net.exe or net1.exe"
id: 7b6cb08c-0bca-4835-a9f4-fa0286cdc78b
related:
- id: b9f0e6f5-09b4-4358-bae4-08408705bd5c
type: similar
- id: cd219ff3-fa99-45d4-8380-a7d15116c6dc
type: derived
status: test
description: This rule flags process executions where net.exe or net1.exe is launched with command-line arguments containing both "user" and "add", indicating local user creation attempts. Attackers may use this technique to establish persistence by adding new accounts. It relies on Windows process creation telemetry, including the image path and command line content.
references:
- https://eqllib.readthedocs.io/en/latest/analytics/014c3f51-89c6-40f1-ac9c-5688f26090ab.html
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1136.001/T1136.001.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_net_user_add.yml
author: Endgame, JHasenbusch (adapted to Sigma for oscd.community), Huntrule Team
date: 2018-10-30
modified: 2023-02-21
tags:
- attack.persistence
- attack.t1136.001
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith:
- \net.exe
- \net1.exe
- OriginalFileName:
- net.exe
- net1.exe
selection_cli:
CommandLine|contains|all:
- user
- add
condition: all of selection_*
falsepositives:
- Legitimate user creation.
- Better use event IDs for user creation rather than command line rules.
level: medium
license: DRL-1.1
What it detects
This rule flags process executions where net.exe or net1.exe is launched with command-line arguments containing both "user" and "add", indicating local user creation attempts. Attackers may use this technique to establish persistence by adding new accounts. It relies on Windows process creation telemetry, including the image path and command line content.
Known false positives
- Legitimate user creation.
- Better use event IDs for user creation rather than command line rules.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.