Cross-source coverage

T1531 / ATT&CK

Account Access Removal

82 rules · 81 families across 9 sources.

1 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place.

In Windows, Net utility, Set-LocalUser and Set-ADAccountPassword PowerShell cmdlets may be used by adversaries to modify user accounts. Accounts could also be disabled by Group Policy. In Linux, the passwd utility may be used to change passwords. On ESXi servers, accounts can be removed or modified via esxcli (system account set, system account remove).

Adversaries who use ransomware or similar attacks may first perform this and other Impact behaviors, such as Data Destruction and Defacement, in order to impede incident response/recovery before completing the Data Encrypted for Impact objective.

Tactics
Impact
Platforms
Linux · macOS · Windows · SaaS · IaaS · Office Suite · ESXi
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLNSM:Connectionsmacos:unifiedlogesxi:hostdesxi:vpxam365:unifiedm365:signinlogssaas:okta

How MITRE says to detect it DET0120

Account Access Removal via Multi-Platform Audit Correlation

Windows Analytic 0334

Correlated user account modification (reset, disable, deletion) events with anomalous process lineage (e.g., PowerShell or net.exe from an interactive session), especially outside of IT admin change windows or by non-admin users.

  • WinEventLog:Security EventCode=4723, 4724, 4740
  • WinEventLog:Sysmon EventCode=1

Linux Analytic 0335

Password changes or account deletions via 'passwd', 'userdel', or 'chage' preceded by interactive shell or remote command execution from non-privileged accounts.

  • auditd:SYSCALL SYSCALL record where exe contains passwd/userdel/chage and auid != root
  • NSM:Connections Accepted password or publickey for user from remote IP

macOS Analytic 0336

Execution of dscl or sysadminctl commands to disable, delete, or modify users combined with anomalous process ancestry or terminal session launch.

  • macos:unifiedlog command includes dscl . delete or sysadminctl --deleteUser
  • macos:unifiedlog successful sudo or authentication for account not normally associated with admin actions

ESXi Analytic 0337

Invocation of esxcli 'system account remove' from vCLI, SSH, or vSphere API with anomalous user access or outside maintenance windows.

  • esxi:hostd method=RemoveUser or esxcli system account remove invocation
  • esxi:vpxa user login from unexpected IP or non-admin user role

Office Suite Analytic 0338

O365 UnifiedAuditLog entries for Remove-Mailbox or Set-Mailbox with account disable or delete actions correlated with suspicious login locations or MFA bypass.

  • m365:unified Remove-Mailbox, Set-Mailbox
  • m365:signinlogs Sign-in from anomalous location or impossible travel condition

SaaS Analytic 0339

Deletion or disablement of user accounts in platforms like Okta, Salesforce, or Zoom with anomalies in admin session attributes or mass actions within short duration.

  • saas:okta user.lifecycle.delete, user.account.lock

Wazuh Core Ruleset

25 rules
Detection Severity Format
Logon Failure - Account locked out Medium Wazuh XML
Logon Failure - User not allowed to login at this computer Medium Wazuh XML
Security enabled group deleted Medium Wazuh XML
User account disabled or deleted Medium Wazuh XML
User account locked out (multiple login errors) Medium Wazuh XML
Windows: Logon Failure - Account locked out. Medium Wazuh XML
Windows: User account disabled or deleted. Medium Wazuh XML
Windows: User account locked out (multiple login errors). Medium Wazuh XML
Auditd: User-space account deletion ended abnormally. Low Wazuh XML
Computer account added/changed/deleted Low Wazuh XML

+ 15 more from Wazuh Core Ruleset → showing the 10 highest-severity

panther-labs/panther-analysis

15 rules
Detection Severity Format
Slack Primary Owner Transferred Critical Panther Python
AWS RDS Instance or Cluster Deleted High Panther Python
Zendesk User Suspension Status Changed High Panther Python
AppOmni Alert Passthrough Medium Panther Python
Crowdstrike Allowlist Removed Medium Panther Python
Crowdstrike API Key Deleted Medium Panther Python
OneLogin Multiple Accounts Deleted Medium Panther Python
OneLogin Multiple Accounts Modified Medium Panther Python
Slack Organization Deleted Medium Panther Python
Slack User Privileges Changed to User Medium Panther Python

+ 5 more from panther-labs/panther-analysis → showing the 10 highest-severity

elastic/detection-rules

14 rules
Detection Severity Format
AWS IAM Deactivation of MFA Device High Elastic TOML
Google Workspace MFA Enforcement Disabled For Organization High Elastic TOML
Account Password Reset Remotely Medium Elastic TOML
AWS Account Closed Medium Elastic TOML
AWS Attempt to Leave Organization Medium Elastic TOML
GCP Service Account Deletion Medium Elastic TOML
GCP Service Account Disabled Medium Elastic TOML
Google Workspace Admin Role Deletion Medium Elastic TOML
Attempt to Revoke Okta API Token Low Elastic TOML
AWS IAM Group Deletion Low Elastic TOML

+ 4 more from elastic/detection-rules → showing the 10 highest-severity

SigmaHQ/sigma

9 rules
Detection Severity Format
AWS SAML Provider Deletion Activity Medium Sigma
Azure Kubernetes Service Account Modified or Deleted Medium Sigma
Google Cloud Service Account Disabled or Deleted Medium Sigma
Group Has Been Deleted Via Groupdel Medium Sigma
Okta User Account Locked Out Medium Sigma
Remove Account From Domain Admin Group Medium Sigma
User Has Been Deleted Via Userdel Medium Sigma
AWS ElastiCache Security Group Modified or Deleted Low Sigma
User Logoff Event Informational Sigma

socfortress/Wazuh-Rules

9 rules
Detection Severity Format
Execution of passwd detected - potential account access modification High Wazuh XML
operation. · office_365.Operation = Delete device. High Wazuh XML
operation. · office_365.Operation = Delete user. High Wazuh XML
operation. · office_365.Operation = Disable account. High Wazuh XML
Sysmon - Event 1: Process creation · Azure AD User Deletion PowerShell (T1531) High Wazuh XML
Sysmon - Event 1: Process creation · Delete User with net.exe (T1531) High Wazuh XML
Sysmon - Event 1: Process creation · Remove from Domain Admins (PowerShell) (T1531) High Wazuh XML
Password change attempt detected (T1531 - Account Access Removal) Medium Wazuh XML
Sysmon - Event 1: Process creation · Change Password with net.exe (T1531) Low Wazuh XML

splunk/security_content

6 rules
Detection Severity Format
Cisco ASA - User Account Deleted From Local Database Undefined SPL
Windows Account Access Removal via Logoff Exec Undefined SPL
Windows Excessive Usage Of Net App Undefined SPL
Windows Powershell Logoff User via Quser Undefined SPL
Windows User Deletion Via Net Undefined SPL
Windows User Disabled Via Net Undefined SPL

Azure/Azure-Sentinel

2 rules
Detection Severity Format
AD Account Lockout Undefined KQL
Multiple Entra ID Admins Removed Undefined KQL

chronicle/detection-rules

1 rule
Detection Severity Format
gcp_multiple_hmac_keys_deleted High YARA-L

elastic/protections-artifacts

1 rule
Detection Severity Format
SSH Authorized Keys File Deletion Undefined Elastic TOML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.