Splunk Enterprise Security

ES detected "Default Account at Rest" - How do you fix this?

mgiddens
Path Finder

Good morning,

I have been receiving a notable even in ES that states there are default accounts at rest on a certain search head. No other search heads are popping for this notable event. The message states that a default account allows for authentication. The account is "halt' and "admin"I have tried so many things to fix this; locking password, disabling account by setting the age to expire the account,etc; nothing seems to work. I have verified the /etc/passwd file, permissions on sbin/halt and etc/passwd,, and any configurations withing these files or locations as applicable but not sure where else to go from there to fix this. settings. Does anyone have any clue how to remediate this error?

Thank you,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The CS is looking for events from the Compute_Inventory.Default_Accounts data set where 'enabled' is not zero or "false", 'status' is not "Degraded", 'shell' is not "*nologin" or "*false". and the user is not 'root'. Fix any of those and the account should no longer appear.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mgiddens
Path Finder

Thanks for the feedbaack! I have tried several things to disable the account, change the expiration, changed to "nologin" in sbin, disabled password, and expired the account with "chage" commnad. Still receiving the notable event. So what would I need to check besides this and where would I check it on the server in question? What would I need to change about this account to make this stop?

Thanks again, I appreciate any help you can provide.

mgiddens

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I don't know enough about Windows user administration to answer.

---
If this reply helps you, Karma would be appreciated.
0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...