Windows Registry: Hidden User via Winlogon SpecialAccounts Userlist Value 0

Alerts on Windows registry updates that set Winlogon SpecialAccounts Userlist to DWORD 0 to hide users.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems), frack113 (SigmaHQ), DRL 1.1
Published
2022-07-12
Updated
2026-07-30

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule flags registry changes that set the Winlogon SpecialAccounts Userlist value to DWORD 0x00000000, matching a common technique to hide a user account from the Windows logon screen. Attackers use this to reduce account visibility and complicate discovery by defenders and users. The detection relies on registry set telemetry identifying the specific TargetObject path and the Details value of DWORD (0x00000000).

Related detections7 linkedT1564.002 — drag to rearrange
Suspicious Hidden Account Creation via Winlogon SpecialAccounts UserList Registry
Hiding local user accounts
Malicious Hidden Local Account via Winlogon SpecialAccounts UserList
Suspicious Hidden Local Account via SpecialAccounts UserList Registry Value (via registry_set)
Windows Process Creation: Suspicious secedit.exe Security Policy Export or Configuration
Windows Process Creation: reg.exe Adds Winlogon SpecialAccounts Userlist Value 0
macOS Hidden User Creation via dscl (Hidden Account or UniqueID<500)
Windows Registry: Hidden User via Winlogon SpecialAccounts Userlist Value 0
Pivot detection · T1564.002 · 7 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.