ATT&CK · T1078.003 · sub-technique
Local Accounts
Tactics: stealth, persistence, privilege-escalation, initial-access
About
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service. Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.
Used by actors
12 known groups
Software
5 malware/tools implement this
Corpus indicators tagged with this technique
31 indicators in the corpus carry T1078.003.
Showing the top 30 by severity of 31.