Unusual user account enablement
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Account Manipulation (T1098)
Severity
Informational
Description
A user enabled an account. This user does not usually enable user accounts.
Attacker's Goals
An attacker may enable a user account to gain persistence.
Investigative actions
Investigate the associated enabling event.
Check if the user is authorized to enable accounts.
Confirm that the account enablement was expected.
If the account enablement seems suspicious, address it accordingly by disabling the account again, forcing a password change, or monitoring its activity.
Variations
Was this helpful?
