kevmap

TechniquesT1136 › AN1604

AN1604 Analytic 1604

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Adversary uses built-in OS tools or API calls to create local or domain accounts for persistence or lateral movement. Tools such as 'net user', PowerShell, or MMC snap-ins may be used. Detection focuses on Event ID 4720 paired with process lineage and user context.</p>
Detects
T1136 Create Account
Part of
DET0583 Detection Strategy for T1136 - Create Account across platforms

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4720DC0014 User Account Creation
WinEventLog:SysmonEventCode=1DC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TimeWindowCorrelation between Event ID 4720 and creating process may vary by environment and automation delays
ParentProcessNameTools like net.exe or powershell.exe can be normal or malicious depending on user context
UserContextSystem vs. administrator vs. low-privilege user context changes alert criticality

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2021-34473Microsoft Exchange ServerMapped
CVE-2021-40539Zoho ManageEngineMapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter PlusMapped
CVE-2023-20198Cisco IOS XE Web UIMapped
CVE-2023-22515Atlassian Confluence Data Center and ServerMapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPNMapped
CVE-2023-28252Microsoft WindowsMapped
CVE-2023-34362Progress MOVEit TransferMapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2025-31161CrushFTP CrushFTPMapped