M ManySignal
T1136 MITRE ATT&CK

T1136 Create Account — Detection & Response

Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.

Coverage at a glance

Detections shipped
3
Avg. verdict time
< 5 min
Data sources
3+

Threat context

How adversaries use T1136 Create Account — Detection & Response

Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.

Account creation is a reliable persistence mechanism that survives password policy changes on the compromised account. In cloud environments (T1136.003), attackers create new IAM users or service accounts with API keys that persist even if the original compromised user's credentials are rotated. In Active Directory (T1136.002), rogue accounts are often created in OUs with lax monitoring and assigned to groups with excessive privileges.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

New IAM User Created Outside Provisioning Pipeline — CreateUser not from Terraform or HR system

A new IAM user is created by a principal that is not the expected automation role, indicating rogue account creation.

High AWS CloudTrail

New AD User Without HR Event — Domain account created with no correlated onboarding event

A new domain user account is created without a corresponding approved onboarding change request, a potential indicator of rogue account creation.

High Active Directory

New Okta User by Non-Admin — User created by non-provisioning role

An Okta user account is created by an account that does not normally have provisioning authority.

High Okta

T1136 Create Account — Detection & Response: frequently asked questions

How does ManySignal differentiate legitimate account provisioning from rogue account creation?

ManySignal learns the normal provisioning pattern — which principals create accounts, at what time of day, and through which IAM roles. Deviations from this pattern (wrong creator, unusual time, unusual permissions granted at creation) trigger alerts.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.