Account Access Removal T1531
Tactic: Impact
Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place.
Events covered
8 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4624 | An account was successfully logged on. |
| Security-Auditing | Event ID 4634 | An account was logged off. |
| Security-Auditing | Event ID 4647 | User initiated logoff. |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| Security-Auditing | Event ID 4724 | An attempt was made to reset an account's password. |
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
These 66 rules share fields, values, and exclusions.
Fields filtered most (74 distinct)
These fields appear most often in rule filters.
Top indicator values (208 distinct)
These values appear most often in rule predicates.
Exclusions (31 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 10 rules
- AWS ElastiCache Security Group Modified or Deleted
- AWS SAML Provider Deletion Activity
- Azure Kubernetes Service Account Modified or Deleted
- Google Cloud Service Account Disabled or Deleted
- Group Has Been Deleted Via Groupdel
- IAM Login Profile Deleted
- Okta User Account Locked Out
- Remove Account From Domain Admin Group
- User Has Been Deleted Via Userdel
- User Logoff Event
Elastic 18 rules
- Account Password Reset Remotely
- Attempt to Revoke Okta API Token
- AWS Account Closed
- AWS Attempt to Leave Organization
- AWS IAM Deactivation of MFA Device
- AWS IAM Group Deletion
- GCP IAM Role Deletion
- GCP IAM Service Account Key Deletion
- GCP Service Account Deletion
- GCP Service Account Disabled
- GitHub PAT Access Revoked
- GitHub User Blocked From Organization
- Google Workspace Admin Role Deletion
- Google Workspace MFA Enforcement Disabled For Organization
- Linux User or Group Deletion
- Member Removed From GitHub Organization
- SSH Authorized Keys File Deletion
- SSH Authorized Keys File Deletion
Splunk 8 rules
- Account Password Changed from Command Line - Windows (PowerShell)
- Account Password Changed from Command Line - Windows (Windows Event Log)
- Cisco ASA - User Account Deleted From Local Database
- Windows Account Access Removal via Logoff Exec
- Windows Excessive Usage Of Net App
- Windows Powershell Logoff User via Quser
- Windows User Deletion Via Net
- Windows User Disabled Via Net
Kusto 14 rules
- Cisco Duo - Admin user deleted
- Cisco Duo - Multiple users deleted
- Commvault Cloud Alert
- Jira - Permission scheme updated
- Jira - Project roles changed
- Jira - User removed from group
- Jira - User removed from project
- Multiple admin membership removals from newly created admin.
- SAP BTP - Build Work Zone unauthorized access and role tampering
- SAP BTP - Mass user deletion in a sub account
- SAP BTP - Mass user deletion in Cloud Identity Service
- Threat Essentials - Multiple admin membership removals from newly created admin.
- Valimail Enforce - High-Value User Management Event
- Valimail Enforce - Unusual Rate of Configuration Changes or User Additions
YARA-L 1 rule
Panther 15 rules
- Anthropic Organization User Deleted
- AppOmni Alert Passthrough
- AWS RDS Instance or Cluster Deleted
- Crowdstrike Allowlist Removed
- Crowdstrike API Key Deleted
- Databricks Group Deleted
- Databricks User Account Deleted
- OneLogin Multiple Accounts Deleted
- OneLogin Multiple Accounts Modified
- Slack Organization Deleted
- Slack Primary Owner Transferred
- Slack User Privileges Changed to User
- Wiz Revoke User Sessions
- Zendesk User Suspension Status Changed
- ZIA Account Access Removed