Windows Local User Creation (Security Event 4720)

Flags Windows Security Event ID 4720 indicating a local user account was created.

FreeReviewedSigma · Low · v2
Product
windows
Service
security
Author
Patrick Bareiss (SigmaHQ), DRL 1.1
Published
2019-04-18
Updated
2026-07-31

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows Security Event ID 4720, which indicates creation of a new local user account. Attackers may use local accounts to establish persistence when they can write credentials or create identities outside centralized domain controls. Detection relies on Security log telemetry from Windows where event 4720 is recorded. Benign cases include activity on domain controllers and account management performed by approved privileged tools.

Related detections9 linkedT1136.001 — drag to rearrange
Suspicious Local Account Creation via Net User in Pre-Ransomware Phase
Suspicious Hidden Local Account Creation via Net User by UAT-8099
Malicious Local Account Creation of Support or Whiteninja via net.exe
Malicious Dynamicweb Unauthenticated Administrator Creation via Setup Default.aspx (via webserver)
Suspicious Hidden Backdoor Account Creation Ending With Dollar Sign (via process_creation)
Malicious User Creation via Commandline (via process_creation)
Suspicious Local Account Creation and Privileged Group Addition via Net.EXE (via process_creation)
Suspicious Hidden Local Account Creation via Dscl (via process_creation)
Suspicious Local Account Creation on Linux (via process_creation)
Windows Local User Creation (Security Event 4720)
Pivot detection · T1136.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.