Analytics BIOC
Informational
✕
Unusual user account enablement
A user enabled an account. This user does not usually enable user accounts.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098)
Attacker's goals:
An attacker may enable a user account to gain persistence.
Investigative actions:
Investigate the associated enabling event. Check if the user is authorized to enable accounts. Confirm that the account enablement was expected. If the account enablement seems suspicious, address it accordingly by disabling the account again, forcing a password change, or monitoring its activity.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Unusual sensitive user account enablement Low (parent: Informational)