Account Access Removal T1531

Tactic: Impact

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place.

Events covered

8 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 66 rules share fields, values, and exclusions.

Fields filtered most (74 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType17eq 12, wildcard 4, in 1DELETE, allow_strong_authentication, closeaccount, deactivatemfadevice, delete_role
data_stream.dataset11eq 11aws.cloudtrail, gcp.audit, google_workspace.admin, okta.system
event.outcome9eq 9success
action6eq 5, in 1RevokeUserSessions, create, delete, organization_deleted, role_change_to_user
process_name5eq 5, in 1, starts_with 1net1.exe, ., bash, busybox, logoff.exe
CommandLine4contains 2, regex_match 2(?i)net1?(\.exe)?\s+user\s+\S+\s+\S+, user, /active:no, /delete
EventID4eq 44104, 4688, storage.hmacKeys.delete
EventMessage4eq 4permission scheme updated, project roles changed, user removed from group, user removed from project
Provider_Name4eq 3, in 1iam.amazonaws.com, organizations.amazonaws.com, account.amazonaws.com
aws::eventName4eq 3, in 1DeleteDBCluster, DeleteDBInstance, authorizecachesecuritygroupegress, authorizecachesecuritygroupingress, deletecachesecuritygroup
aws::eventSource4eq 4iam.amazonaws.com, elasticache.amazonaws.com, rds.amazonaws.com
Image3ends_with 2, starts_with 1./, /boot/, /dev/shm/, /groupdel, /userdel
OriginalFileName3eq 3net1.exe
event.dataset3eq 3github.audit
event.type3eq 3, in 1deletion, group, start, user

Top indicator values (208 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
9369
data_stream.dataseteq
aws.cloudtrail
4169
data_stream.dataseteq
gcp.audit
469
data_stream.dataseteq
google_workspace.admin
218
OriginalFileNameeq
net1.exe
344
event.dataseteq
github.audit
314
event.typeeq
deletion
316
process_nameeq
net1.exe
339
AddedGlobalAdminTimecross_field_compare
RemovedGlobalAdminTime
22
Categoryeq
rolemanagement
221
CommandLinecontains
user
217
CommandLineregex_match
(?i)net1?(\.exe)?\s+user\s+\S+\s+\S+
22
DeletedUsersgt
10
22
EventIDeq
4104
2269
Initiatorne
MS-PIM
26
Initiatorne
MS-PIM-Fairfax
24
NoofAdminsRemovedgt
1
22
Provider_Nameeq
iam.amazonaws.com
232
Resulteq
success
231
RoleNameeq
global administrator
22
aws::eventSourceeq
iam.amazonaws.com
228
azure_ad::activity_display_namecontains
add eligible member to role
210
azure_ad::activity_display_namecontains
add member to role
210
azure_ad::activity_display_namecontains
remove eligible member from role
22
azure_ad::activity_display_namecontains
remove member from role
22
serviceNameeq
accounts
213
AADOperationTypein
Assign
16
AADOperationTypein
AssignEligibleRole
15
AADOperationTypein
RemoveEligibleRole
1
AADOperationTypein
Unassign
1

Exclusions (31 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLineregex_match
(?i)\/\S+
2
Imagein
/bin/dockerd
1
Imagein
/usr/bin/containerd
1
Imagein
/usr/bin/dockerd
1
Imagein
/usr/bin/google_guest_agent
1
Imagestarts_with
/nix/store/
1
TargetFilenamecontains
ansible
1
TargetFilenamecontains
backup
1
TargetFilenamecontains
puppet
1
TargetFilenamewildcard
/home/*/*/.ssh/*
1
TargetUserNamewildcard
*$
1
TargetUserNamewildcard
*-*-*
1
TargetUserNamewildcard
PIM_*
1
TargetUserNamewildcard
_*_
1
TargetUserNamewildcard
svc*
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 10 rules

Elastic 18 rules

Splunk 8 rules

Kusto 14 rules

YARA-L 1 rule

Panther 15 rules