User account created and deleted within 10 mins

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies when a user account is created and then deleted within 10 minutes. This can be an indication of compromise and an adversary attempting to hide in the noise.

Attribute Value
Type Analytic Rule
Solution Standalone Content
ID 4b93c5af-d20b-4236-b696-a28b8c51407f
Severity Medium
Kind Scheduled
Tactics Persistence, PrivilegeEscalation
Techniques T1098, T1078
Required Connectors SecurityEvents, WindowsSecurityEvents, WindowsForwardedEvents
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules