← LibraryTechnique entry
T1136Persistence
Create Account
Create accounts on the system or domain.
§ Where this technique fits
T1136 is catalogued under the Persistence tactic of the offensive-security kill-chain. It appears in 2 approved dossiers in the registry, typically at step 2 on average.
Authoritative reference: attack.mitre.org/techniques/T1136/.
§ Dossiers chaining this technique
- step 2 / 7
noPac / sAMAccountName spoofing → Domain Admin
Combine CVE-2021-42278 (sAMAccountName validation) and CVE-2021-42287 (PAC confusion) to impersonate a DC as a low-priv user.
- step 2 / 5
RBCD abuse → SYSTEM on a domain host
A user with GenericAll/GenericWrite on a computer object writes msDS-AllowedToActOnBehalfOfOtherIdentity, then uses S4U2self/S4U2proxy to impersonate any user (including Administrator) on that host.
§ What commonly comes next
- 01Resource-Based Constrained Delegation (RBCD) Abuseseen 1×AD-RBCD · Lateral Movement
- 02sAMAccountName Spoofing — noPac (CVE-2021-42278/42287)seen 1×AD-NOPAC · Privilege Escalation