For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual user account unlock

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Analytics

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Informational

Description

A user unlocked an account. This user does not usually unlock user accounts.

Attacker's Goals

An attacker may unlock a user account to gain unauthorized access.

Investigative actions

  • Investigate the associated authentication attempts and login failures (e.g. 4625, 4776 events).

  • Check if the user is authorized to unlock accounts.

  • Confirm that the user unlock was expected.

  • Monitor services that may be running with a user's credentials, resulting in lockouts.

Variations

Unusual sensitive user account unlock

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Low

Description

A user unlocked a sensitive account. This user does not usually unlock user accounts.

Attacker's Goals

An attacker may unlock a user account to gain unauthorized access.

Investigative actions

  • Investigate the associated authentication attempts and login failures (e.g. 4625, 4776 events).

  • Check if the user is authorized to unlock accounts.

  • Confirm that the user unlock was expected.

  • Monitor services that may be running with a user's credentials, resulting in lockouts.

Was this helpful?