Skip to content

Rogue Account

Definition

A user or service account created by the attacker during the intrusion to maintain access independent of any compromised legitimate account. Rogue accounts may be given names designed to blend with legitimate accounts and may be added to privileged groups.

Created by
The attacker, during the intrusion
Purpose
Maintain access independent of any compromised legitimate account
Naming tactic
May mimic legitimate account naming conventions
Privilege risk
May be added to privileged groups

Common questions

How is a rogue account different from a compromised legitimate account?+

A compromised account belonged to a real user before the attacker took it over, while a rogue account is entirely fabricated by the attacker, giving them access that does not depend on the original user ever noticing suspicious activity on their own credentials.

Why does eradication require finding all rogue accounts before restoring trust?+

Resetting only the accounts known to be compromised leaves any rogue account the attacker created untouched, giving them a persistent foothold that survives the incident response and allows re-entry after remediation is declared complete.

What review steps typically surface a rogue account during incident response?+

A full audit of account creation timestamps, group membership changes, and authentication logs against the change-management baseline, cross-referenced with HR records to confirm every account maps to a real, authorised user.

Related terms

Configuration Drift
Deviation from an approved baseline configuration, whether caused by legitimate administrative action or by an attacker modifying settings to weaken defences or...
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
Persistence Mechanism
The technique malware uses to survive a reboot or user logout. Common methods include registry run keys, scheduled tasks, Windows services, cron...
Reimaging
Wiping a compromised system and restoring it from a known-good operating system image. Reimaging is the most reliable eradication method for host-level...
Web Shell
A script (typically PHP, ASP, or JSP) placed on a web server by an attacker to provide remote command execution via HTTP...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.