Cross-source coverage
T1531 / ATT&CK
Account Access Removal
82 rules · 81 families across 9 sources.
1 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place.
In Windows, Net utility, Set-LocalUser and Set-ADAccountPassword PowerShell cmdlets may be used by adversaries to modify user accounts. Accounts could also be disabled by Group Policy. In Linux, the passwd utility may be used to change passwords. On ESXi servers, accounts can be removed or modified via esxcli (system account set, system account remove).
Adversaries who use ransomware or similar attacks may first perform this and other Impact behaviors, such as Data Destruction and Defacement, in order to impede incident response/recovery before completing the Data Encrypted for Impact objective.
- Tactics
- Impact
- Platforms
- Linux · macOS · Windows · SaaS · IaaS · Office Suite · ESXi
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLNSM:Connectionsmacos:unifiedlogesxi:hostdesxi:vpxam365:unifiedm365:signinlogssaas:okta
How MITRE says to detect it DET0120
Account Access Removal via Multi-Platform Audit Correlation
Windows Analytic 0334
Correlated user account modification (reset, disable, deletion) events with anomalous process lineage (e.g., PowerShell or net.exe from an interactive session), especially outside of IT admin change windows or by non-admin users.
WinEventLog:SecurityEventCode=4723, 4724, 4740WinEventLog:SysmonEventCode=1
Linux Analytic 0335
Password changes or account deletions via 'passwd', 'userdel', or 'chage' preceded by interactive shell or remote command execution from non-privileged accounts.
auditd:SYSCALLSYSCALL record where exe contains passwd/userdel/chage and auid != rootNSM:ConnectionsAccepted password or publickey for user from remote IP
macOS Analytic 0336
Execution of dscl or sysadminctl commands to disable, delete, or modify users combined with anomalous process ancestry or terminal session launch.
macos:unifiedlogcommand includes dscl . delete or sysadminctl --deleteUsermacos:unifiedlogsuccessful sudo or authentication for account not normally associated with admin actions
ESXi Analytic 0337
Invocation of esxcli 'system account remove' from vCLI, SSH, or vSphere API with anomalous user access or outside maintenance windows.
esxi:hostdmethod=RemoveUser or esxcli system account remove invocationesxi:vpxauser login from unexpected IP or non-admin user role
Office Suite Analytic 0338
O365 UnifiedAuditLog entries for Remove-Mailbox or Set-Mailbox with account disable or delete actions correlated with suspicious login locations or MFA bypass.
m365:unifiedRemove-Mailbox, Set-Mailboxm365:signinlogsSign-in from anomalous location or impossible travel condition
SaaS Analytic 0339
Deletion or disablement of user accounts in platforms like Okta, Salesforce, or Zoom with anomalies in admin session attributes or mass actions within short duration.
saas:oktauser.lifecycle.delete, user.account.lock
Wazuh Core Ruleset
25 rules| Detection | Severity | Format |
|---|---|---|
| Logon Failure - Account locked out | Medium | Wazuh XML |
| Logon Failure - User not allowed to login at this computer | Medium | Wazuh XML |
| Security enabled group deleted | Medium | Wazuh XML |
| User account disabled or deleted | Medium | Wazuh XML |
| User account locked out (multiple login errors) | Medium | Wazuh XML |
| Windows: Logon Failure - Account locked out. | Medium | Wazuh XML |
| Windows: User account disabled or deleted. | Medium | Wazuh XML |
| Windows: User account locked out (multiple login errors). | Medium | Wazuh XML |
| Auditd: User-space account deletion ended abnormally. | Low | Wazuh XML |
| Computer account added/changed/deleted | Low | Wazuh XML |
+ 15 more from Wazuh Core Ruleset → showing the 10 highest-severity
panther-labs/panther-analysis
15 rules| Detection | Severity | Format |
|---|---|---|
| Slack Primary Owner Transferred | Critical | Panther Python |
| AWS RDS Instance or Cluster Deleted | High | Panther Python |
| Zendesk User Suspension Status Changed | High | Panther Python |
| AppOmni Alert Passthrough | Medium | Panther Python |
| Crowdstrike Allowlist Removed | Medium | Panther Python |
| Crowdstrike API Key Deleted | Medium | Panther Python |
| OneLogin Multiple Accounts Deleted | Medium | Panther Python |
| OneLogin Multiple Accounts Modified | Medium | Panther Python |
| Slack Organization Deleted | Medium | Panther Python |
| Slack User Privileges Changed to User | Medium | Panther Python |
+ 5 more from panther-labs/panther-analysis → showing the 10 highest-severity
elastic/detection-rules
14 rules| Detection | Severity | Format |
|---|---|---|
| AWS IAM Deactivation of MFA Device | High | Elastic TOML |
| Google Workspace MFA Enforcement Disabled For Organization | High | Elastic TOML |
| Account Password Reset Remotely | Medium | Elastic TOML |
| AWS Account Closed | Medium | Elastic TOML |
| AWS Attempt to Leave Organization | Medium | Elastic TOML |
| GCP Service Account Deletion | Medium | Elastic TOML |
| GCP Service Account Disabled | Medium | Elastic TOML |
| Google Workspace Admin Role Deletion | Medium | Elastic TOML |
| Attempt to Revoke Okta API Token | Low | Elastic TOML |
| AWS IAM Group Deletion | Low | Elastic TOML |
+ 4 more from elastic/detection-rules → showing the 10 highest-severity
SigmaHQ/sigma
9 rules| Detection | Severity | Format |
|---|---|---|
| AWS SAML Provider Deletion Activity | Medium | Sigma |
| Azure Kubernetes Service Account Modified or Deleted | Medium | Sigma |
| Google Cloud Service Account Disabled or Deleted | Medium | Sigma |
| Group Has Been Deleted Via Groupdel | Medium | Sigma |
| Okta User Account Locked Out | Medium | Sigma |
| Remove Account From Domain Admin Group | Medium | Sigma |
| User Has Been Deleted Via Userdel | Medium | Sigma |
| AWS ElastiCache Security Group Modified or Deleted | Low | Sigma |
| User Logoff Event | Informational | Sigma |
socfortress/Wazuh-Rules
9 rules| Detection | Severity | Format |
|---|---|---|
| Execution of passwd detected - potential account access modification | High | Wazuh XML |
| operation. · office_365.Operation = Delete device. | High | Wazuh XML |
| operation. · office_365.Operation = Delete user. | High | Wazuh XML |
| operation. · office_365.Operation = Disable account. | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Azure AD User Deletion PowerShell (T1531) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Delete User with net.exe (T1531) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Remove from Domain Admins (PowerShell) (T1531) | High | Wazuh XML |
| Password change attempt detected (T1531 - Account Access Removal) | Medium | Wazuh XML |
| Sysmon - Event 1: Process creation · Change Password with net.exe (T1531) | Low | Wazuh XML |
splunk/security_content
6 rules| Detection | Severity | Format |
|---|---|---|
| Cisco ASA - User Account Deleted From Local Database | Undefined | SPL |
| Windows Account Access Removal via Logoff Exec | Undefined | SPL |
| Windows Excessive Usage Of Net App | Undefined | SPL |
| Windows Powershell Logoff User via Quser | Undefined | SPL |
| Windows User Deletion Via Net | Undefined | SPL |
| Windows User Disabled Via Net | Undefined | SPL |
Azure/Azure-Sentinel
2 rules| Detection | Severity | Format |
|---|---|---|
| AD Account Lockout | Undefined | KQL |
| Multiple Entra ID Admins Removed | Undefined | KQL |
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| gcp_multiple_hmac_keys_deleted | High | YARA-L |
elastic/protections-artifacts
1 rule| Detection | Severity | Format |
|---|---|---|
| SSH Authorized Keys File Deletion | Undefined | Elastic TOML |