Splunk Enterprise Security

ES detected "Default Account at Rest" - How do you fix this?

mgiddens
Path Finder

Good morning,

I have been receiving a notable even in ES that states there are default accounts at rest on a certain search head. No other search heads are popping for this notable event. The message states that a default account allows for authentication. The account is "halt' and "admin"I have tried so many things to fix this; locking password, disabling account by setting the age to expire the account,etc; nothing seems to work. I have verified the /etc/passwd file, permissions on sbin/halt and etc/passwd,, and any configurations withing these files or locations as applicable but not sure where else to go from there to fix this. settings. Does anyone have any clue how to remediate this error?

Thank you,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The CS is looking for events from the Compute_Inventory.Default_Accounts data set where 'enabled' is not zero or "false", 'status' is not "Degraded", 'shell' is not "*nologin" or "*false". and the user is not 'root'. Fix any of those and the account should no longer appear.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mgiddens
Path Finder

Thanks for the feedbaack! I have tried several things to disable the account, change the expiration, changed to "nologin" in sbin, disabled password, and expired the account with "chage" commnad. Still receiving the notable event. So what would I need to check besides this and where would I check it on the server in question? What would I need to change about this account to make this stop?

Thanks again, I appreciate any help you can provide.

mgiddens

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I don't know enough about Windows user administration to answer.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...