What MITRE ATT&CK T1136: Create Account (Enterprise Tactic TA0003 - Persistence) requires
MITRE ATT&CK T1136 describes adversary creation of accounts to maintain access. Sub-techniques cover Local Account (T1136.001), Domain Account (T1136.002), and Cloud Account (T1136.003). Adversary-created accounts often evade detection by appearing legitimate; SolarWinds and Hafnium (Microsoft Exchange ProxyLogon) campaigns both used this technique. Compliance obligations include identity governance and account lifecycle monitoring required by NIST 800-53 AC-2, ISO A.5.16, and DORA Article 9, plus mandatory privileged account oversight under PCI DSS Req 7 and HIPAA 164.308(a)(4).
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1136/
SHA-256 integrity: 1551e62419b65855465540ae11b58f7fcd35278175bb5e3f2507c7d0beead6ef
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1136: Create Account (https://attack.mitre.org/techniques/T1136/) with sub-techniques for Local Account, Domain Account, and Cloud Account
- NIST SP 800-53 Rev 5: AC-2 (Account Management) including automated controls; IA-4 (Identifier Management)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.