For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual user account enablement

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Analytics

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation (T1098)

Severity

Informational

Description

A user enabled an account. This user does not usually enable user accounts.

Attacker's Goals

An attacker may enable a user account to gain persistence.

Investigative actions

  • Investigate the associated enabling event.

  • Check if the user is authorized to enable accounts.

  • Confirm that the account enablement was expected.

  • If the account enablement seems suspicious, address it accordingly by disabling the account again, forcing a password change, or monitoring its activity.

Variations

Unusual sensitive user account enablement

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation (T1098)

Severity

Low

Description

A user enabled a sensitive account. This user does not usually enable user accounts.

Attacker's Goals

An attacker may enable a user account to gain persistence.

Investigative actions

  • Investigate the associated enabling event.

  • Check if the user is authorized to enable accounts.

  • Confirm that the account enablement was expected.

  • If the account enablement seems suspicious, address it accordingly by disabling the account again, forcing a password change, or monitoring its activity.

Was this helpful?