Detection of Linux User Account Creation for Persistence
Attackers frequently create new local user accounts on Linux systems to establish and maintain persistence following initial compromise.
The creation of new user accounts on Linux systems is a common technique used by threat actors to maintain unauthorized access to a compromised environment. By leveraging standard system utilities such as useradd or adduser, an adversary can establish a new local account that provides long-term persistence, bypasses session timeouts, and potentially grants higher-level privileges if added to groups like sudo or wheel.
While account creation is a routine administrative task in enterprise environments, it remains a critical signal in security monitoring. Defenders should correlate these events with the identity performing the action and the context of the host to differentiate between legitimate IT provisioning and unauthorized persistent access attempts.
Impact
Successful account creation allows adversaries to maintain persistence even if initial access credentials are changed or revoked. This can lead to persistent data exfiltration, lateral movement, or the staging of further malicious activity. If unauthorized accounts are not detected and remediated, the attacker maintains a persistent foothold in the environment until the account is explicitly identified and removed.
Recommendation
- Deploy the provided detection logic to identify
useraddandadduseractivity across all Linux hosts. - Establish a baseline of authorized administrative accounts and automated service accounts that legitimately perform user creation to reduce alert noise.
- When an alert triggers, use the provided Osquery queries to verify if the account is active, verify group memberships, and investigate the parent process tree for the process that initiated the user creation.
- Enable Filebeat System Module logs on all Linux endpoints to ensure the necessary audit telemetry reaches the SIEM.
Immediate actions
Deploy rule to SIEM and baseline administrative user creation behavior
Threat Hunt
Identify all local user accounts created in the last 30 days
Data: System authentication logs
Detection coverage 1
Linux User Account Creation
lowDetects the successful creation of a new local user account on Linux systems via system authentication logs.
Detection queries are available on the platform. Get full rules →