Splunk Enterprise Security

ES detected "Default Account at Rest" - How do you fix this?

mgiddens
Path Finder

Good morning,

I have been receiving a notable even in ES that states there are default accounts at rest on a certain search head. No other search heads are popping for this notable event. The message states that a default account allows for authentication. The account is "halt' and "admin"I have tried so many things to fix this; locking password, disabling account by setting the age to expire the account,etc; nothing seems to work. I have verified the /etc/passwd file, permissions on sbin/halt and etc/passwd,, and any configurations withing these files or locations as applicable but not sure where else to go from there to fix this. settings. Does anyone have any clue how to remediate this error?

Thank you,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The CS is looking for events from the Compute_Inventory.Default_Accounts data set where 'enabled' is not zero or "false", 'status' is not "Degraded", 'shell' is not "*nologin" or "*false". and the user is not 'root'. Fix any of those and the account should no longer appear.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

mgiddens
Path Finder

Thanks for the feedbaack! I have tried several things to disable the account, change the expiration, changed to "nologin" in sbin, disabled password, and expired the account with "chage" commnad. Still receiving the notable event. So what would I need to check besides this and where would I check it on the server in question? What would I need to change about this account to make this stop?

Thanks again, I appreciate any help you can provide.

mgiddens

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I don't know enough about Windows user administration to answer.

---
If this reply helps you, an upvote would be appreciated.
0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>