Skip to content

Hide Navigation Hide TOC

Suspicious Manipulation Of Default Accounts Via Net.EXE (5b768e71-86f2-4879-b448-81061cbae951)

Detects suspicious manipulations of default accounts such as 'administrator' and 'guest'. For example 'enable' or 'disable' accounts or change the password...etc

Cluster A Galaxy A Cluster B Galaxy B Level
Archive via Utility - T1560.001 (00f90846-cbd1-4fc5-9233-df5c2bf2a662) Attack Pattern Suspicious Manipulation Of Default Accounts Via Net.EXE (5b768e71-86f2-4879-b448-81061cbae951) Sigma-Rules 1
Archive Collected Data - T1560 (53ac20cd-aca3-406e-9aa0-9fc7fdc60a5a) Attack Pattern Archive via Utility - T1560.001 (00f90846-cbd1-4fc5-9233-df5c2bf2a662) Attack Pattern 2