LoFP LoFP / t1136.001

t1136.001

TitleTags
a local user can be created for legitimate purposes. investigate the user details to determine if it is authorized.
admin activity
administrative activity
an administrator account can be created for legitimate purposes. investigate the account details to determine if it is authorized.
better use event ids for user creation rather than command line rules.
domain controller logs
legitimate administration activities
legitimate user creation
local accounts managed by privileged account management tools
unknown
unlikely
when remote authentication is in place, this should not change often