The Unwanted Guest
ID: 7bdd1a58-2f49-5f3b-9675-440053fa79e2
STIX ID: report--7bdd1a58-2f49-5f3b-9675-440053fa79e2
Feed Name: Huntress Blog
Huntress analysts observed threat actors enabling the built-in Windows Guest account (normally disabled) as a persistence and privilege-escalation technique: attackers run commands such as "net user Guest /active:yes", change passwords, add the account to Local Administrators and Remote Desktop Users, enable RDP or install remote access tools (AnyDesk), and sometimes create hidden accounts (e.g., DefaultAcount). The report notes use of native utilities (net.exe, wmic, PowerShell) to perform these changes and recommends monitoring EDR for those binaries, tracking account passwords across incidents, alerting on Microsoft-Windows-Security-Auditing/4722 events referencing "Guest", and threat hunting for active Guest accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
