T1136 Create Account — Detection & Response
Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
Coverage at a glance
- Detections shipped
- 3
- Avg. verdict time
- < 5 min
- Data sources
- 3+
Threat context
How adversaries use T1136 Create Account — Detection & Response
Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
Account creation is a reliable persistence mechanism that survives password policy changes on the compromised account. In cloud environments (T1136.003), attackers create new IAM users or service accounts with API keys that persist even if the original compromised user's credentials are rotated. In Active Directory (T1136.002), rogue accounts are often created in OUs with lax monitoring and assigned to groups with excessive privileges.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| New IAM User Created Outside Provisioning Pipeline — CreateUser not from Terraform or HR system A new IAM user is created by a principal that is not the expected automation role, indicating rogue account creation. | High | AWS CloudTrail |
| New AD User Without HR Event — Domain account created with no correlated onboarding event A new domain user account is created without a corresponding approved onboarding change request, a potential indicator of rogue account creation. | High | Active Directory |
| New Okta User by Non-Admin — User created by non-provisioning role An Okta user account is created by an account that does not normally have provisioning authority. | High | Okta |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1539 Steal Web Session Cookie — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response: frequently asked questions
How does ManySignal differentiate legitimate account provisioning from rogue account creation?
ManySignal learns the normal provisioning pattern — which principals create accounts, at what time of day, and through which IAM roles. Deviations from this pattern (wrong creator, unusual time, unusual permissions granted at creation) trigger alerts.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.