{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/adsi/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["persistence","windows","powershell","adsi","detection-engineering"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eSecurity researchers have identified a technique where attackers leverage Active Directory Service Interfaces (ADSI) via PowerShell to create new user accounts on Windows systems. By utilizing the WinNT or LDAP providers directly within PowerShell scripts, an attacker can programmatically interact with the directory service, allowing for user creation without triggering standard detection logic that typically monitors for binaries like net.exe or cmdlets like New-LocalUser. This approach is primarily aimed at persistence and privilege escalation, as it allows for the quiet creation of backdoor accounts. Because this method interacts directly with the underlying directory infrastructure, it is rarely observed in typical day-to-day administrative operations, making it a high-fidelity indicator of potentially malicious activity when detected.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this technique enables attackers to establish persistent access to a compromised machine or domain. By creating hidden or unmonitored accounts, adversaries can maintain a foothold, facilitate lateral movement, and escalate privileges. This method is particularly concerning because it evades common heuristic and signature-based detections focused on standard user management tools, potentially increasing the dwell time of an unauthorized actor within an enterprise environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy the provided Sigma detection rule to monitor for PowerShell command-line activity utilizing ADSI interfaces for user account creation. Investigate any findings to distinguish between legitimate automated provisioning tasks and anomalous creation events.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rule below to your SIEM and enable logging for PowerShell command-line arguments via Sysmon Event ID 1 or native PowerShell script block logging (Event ID 4104).\u003c/li\u003e\n\u003cli\u003eInvestigate any hits in the SOC to determine if the account creation was initiated by authorized IT automation tools or unauthorized scripts.\u003c/li\u003e\n\u003cli\u003eBaseline administrative scripts in your environment that legitimately leverage ADSI to reduce noise from the detection rule.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T22:52:06Z","date_published":"2026-08-18T22:52:06Z","id":"https://feed.craftedsignal.io/briefs/2026-08-adsi-user-creation/","summary":"Adversaries may use Active Directory Service Interfaces (ADSI) within PowerShell to create local or domain accounts, effectively bypassing standard monitoring for typical user-creation commands.","title":"Detection of Stealthy User Account Creation via ADSI","url":"https://feed.craftedsignal.io/briefs/2026-08-adsi-user-creation/"}],"language":"en","title":"CraftedSignal Threat Feed - Adsi","version":"https://jsonfeed.org/version/1.1"}