Analytics BIOC
Informational
✕
Unusual user account unlock
A user unlocked an account. This user does not usually unlock user accounts.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:
An attacker may unlock a user account to gain unauthorized access.
Investigative actions:
Investigate the associated authentication attempts and login failures (e.g. 4625, 4776 events). Check if the user is authorized to unlock accounts. Confirm that the user unlock was expected. Monitor services that may be running with a user's credentials, resulting in lockouts.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Unusual sensitive user account unlock Low (parent: Informational)