Skip to content
Threat Feed
low advisory

Detection of Linux User Account Creation for Persistence

Attackers frequently create new local user accounts on Linux systems to establish and maintain persistence following initial compromise.

The creation of new user accounts on Linux systems is a common technique used by threat actors to maintain unauthorized access to a compromised environment. By leveraging standard system utilities such as useradd or adduser, an adversary can establish a new local account that provides long-term persistence, bypasses session timeouts, and potentially grants higher-level privileges if added to groups like sudo or wheel.

While account creation is a routine administrative task in enterprise environments, it remains a critical signal in security monitoring. Defenders should correlate these events with the identity performing the action and the context of the host to differentiate between legitimate IT provisioning and unauthorized persistent access attempts.

Impact

Successful account creation allows adversaries to maintain persistence even if initial access credentials are changed or revoked. This can lead to persistent data exfiltration, lateral movement, or the staging of further malicious activity. If unauthorized accounts are not detected and remediated, the attacker maintains a persistent foothold in the environment until the account is explicitly identified and removed.

Recommendation

  • Deploy the provided detection logic to identify useradd and adduser activity across all Linux hosts.
  • Establish a baseline of authorized administrative accounts and automated service accounts that legitimately perform user creation to reduce alert noise.
  • When an alert triggers, use the provided Osquery queries to verify if the account is active, verify group memberships, and investigate the parent process tree for the process that initiated the user creation.
  • Enable Filebeat System Module logs on all Linux endpoints to ensure the necessary audit telemetry reaches the SIEM.

Immediate actions

Deploy rule to SIEM and baseline administrative user creation behavior

Detection Engineering 7d

Threat Hunt

Identify all local user accounts created in the last 30 days

T1136.001 medium high confidence hunt now

Data: System authentication logs

Detection coverage 1

Linux User Account Creation

low

Detects the successful creation of a new local user account on Linux systems via system authentication logs.

sigma tactics: persistence techniques: T1136.001 sources: process_creation, linux

Detection queries are available on the platform. Get full rules →