Splunk Enterprise Security

ES detected "Default Account at Rest" - How do you fix this?

mgiddens
Path Finder

Good morning,

I have been receiving a notable even in ES that states there are default accounts at rest on a certain search head. No other search heads are popping for this notable event. The message states that a default account allows for authentication. The account is "halt' and "admin"I have tried so many things to fix this; locking password, disabling account by setting the age to expire the account,etc; nothing seems to work. I have verified the /etc/passwd file, permissions on sbin/halt and etc/passwd,, and any configurations withing these files or locations as applicable but not sure where else to go from there to fix this. settings. Does anyone have any clue how to remediate this error?

Thank you,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The CS is looking for events from the Compute_Inventory.Default_Accounts data set where 'enabled' is not zero or "false", 'status' is not "Degraded", 'shell' is not "*nologin" or "*false". and the user is not 'root'. Fix any of those and the account should no longer appear.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mgiddens
Path Finder

Thanks for the feedbaack! I have tried several things to disable the account, change the expiration, changed to "nologin" in sbin, disabled password, and expired the account with "chage" commnad. Still receiving the notable event. So what would I need to check besides this and where would I check it on the server in question? What would I need to change about this account to make this stop?

Thanks again, I appreciate any help you can provide.

mgiddens

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I don't know enough about Windows user administration to answer.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...