MITRE ATT&CK Technique
T1078.003Local Accounts
- First Reported
- —
- Latest Reported
- —
Official Description
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Local Accounts may also be abused to elevate privileges and harvest credentials through [OS Credential Dumping](https://attack.mitre.org/techniques/T1003). Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.
Local Accounts may also be abused to elevate privileges and harvest credentials through [OS Credential Dumping](https://attack.mitre.org/techniques/T1003). Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.
- Tactics
- Stealth, Persistence, Privilege Escalation, Initial Access
- Platforms
- Containers, ESXi, Linux, macOS, Network Devices, Windows
- Parent Technique
- T1078 · Valid Accounts
- MITRE Version
- 2.0
- Last Modified
- May 12, 2026