Sensitive account password reset attempt
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Account Access Removal (T1531)
Severity
Informational
Description
An attempt was made to reset a sensitive account's password.
Attacker's Goals
An attacker may attempt to gain access to the account.
Investigative actions
Verify this action with the user who performed the change.
Variations
PreviousSending unusual file(s) to an external address
NextSensitive browser credential files accessed by a rare non browser process
Was this helpful?
