User account enabled and disabled within 10 mins

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies when a user account is enabled and then disabled within 10 minutes. This can be an indication of compromise and an adversary attempting to hide in the noise.

Attribute Value
Type Analytic Rule
Solution Standalone Content
ID 3d023f64-8225-41a2-9570-2bd7c2c4535e
Severity Medium
Kind Scheduled
Tactics Persistence, PrivilegeEscalation
Techniques T1098, T1078
Required Connectors SecurityEvents, WindowsSecurityEvents, WindowsForwardedEvents
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules