Carbanak+FIN7
|
The subtechnique was not in scope.
|
APT29
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
20.B.3
|
|
Technique
(Configuration Change (Detections), Alert)
|
A Technique alert detection for account creation was generated for net.exe executing with the command-line arguments to add the new user Toby.
[1]
|
|
Added a new user to the remote host Scranton (10.0.1.4) using net.exe
net.exe adding the user Toby
-
Updates to detections and logging were enabled after the start of the evaluation, so it is identified as a Detection Configuration Change.
[1]