[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fXFrGYYR3MU6nEHnt9Q8B9Be40K4QPmqw0NjDET-IBQ8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"e8764322-75a0-40a8-bf7c-532f00ea18be","attackers-create-fake-admin-accounts-on-domain-controller-for-persistence","0b0bae7e-5b5c-46ee-a629-ae0fe2f2389e","Attackers Create Fake Admin Accounts on Domain Controller for Persistence","Threat actors compromised a domain controller and used legitimate Windows administration tools (dsa.msc) to create three fake user accounts, including one named 'administratr' designed to mimic real administrator accounts. This technique allows attackers to maintain persistent access to the network even after their initial entry point is discovered and closed. The use of typosquatting account names demonstrates how attackers exploit human tendency to overlook subtle naming differences during routine account reviews. Domain controller compromise represents one of the most severe security incidents as it provides attackers with complete control over the Active Directory environment.","**Immediate actions:**\n- Audit all user accounts on domain controllers for suspicious or recently created accounts\n- Enable detailed logging for all Active Directory account creation and modification activities\n- Implement privileged access management (PAM) solutions to control domain controller access\n\n**Long-term improvements:**\n- Establish automated monitoring for new account creation with naming similarity detection\n- Implement least privilege principles with regular reviews of administrative account permissions\n- Deploy User and Entity Behavior Analytics (UEBA) to detect anomalous account usage patterns\n\n**Detection measures:**\n- Configure SIEM alerts for account creation events on domain controllers\n- Implement regular automated scans comparing current accounts against approved baselines",[12,13,14,15,16,17,18,19],"CIS Control 5","CIS Control 6","CIS Control 8","NIST AC-2","NIST AC-6","NIST AU-2","NIST AU-6","MITRE ATT&CK T1136.002","published","2026-05-27T11:20:17.808309+00:00","2026-05-27T11:20:16.622+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fx.com\u002FTheDFIRReport\u002Fstatus\u002F2059586683062874163","on-the-domain-controller-the-actor-used-dsa-msc-to-create-three-persistence-acco-211a2c","On the Domain Controller, the actor used dsa.msc to create three persistence accounts — including...",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":35,"name":36,"slug":37,"description":38,"color":39},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[]]