Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0009 — User Account Deletion
DC0009

User Account Deletion

3 analytic(s) · 2 detection strategy(ies)

Description

The removal of a user, service, or machine account from an operating system, cloud identity management system, or directory service.

Referenced in Analytics

3
AN0113 Analytic 0113 DET0040

Detects adversary activity that removes persistence artifacts such as services, registry keys, scheduled tasks, user accounts, and binaries through commands like `sc delete`, `schtasks /delete`, or `reg delete`.

WinEventLog:Sysmon WinEventLog:Security WinEventLog:TaskScheduler WinEventLog:Security
AN0337 Analytic 0337 DET0120

Invocation of esxcli 'system account remove' from vCLI, SSH, or vSphere API with anomalous user access or outside maintenance windows.

esxi:hostd esxi:vpxa
AN0338 Analytic 0338 DET0120

O365 UnifiedAuditLog entries for Remove-Mailbox or Set-Mailbox with account disable or delete actions correlated with suspicious login locations or MFA bypass.

m365:unified m365:signinlogs

Details

MITRE ID
DC0009
STIX ID
x-mitre-data-component--d6257b8e-869c-41c0-8731-fdca40858a91
Analytics
3
Detection Strategies
2
Leaving Threaticon

This link opens an external site that isn't part of the platform.