1200KM / detection
T1531 Account Access Removal — Detection Rules
Detection workspace for T1531 Account Access Removal: 9 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- AWS SAML Provider Deletion Activity · experimental · medium · {"product":"aws","service":"cloudtrail"}
- AWS ElastiCache Security Group Modified or Deleted · test · low · {"product":"aws","service":"cloudtrail"}
- Azure Kubernetes Service Account Modified or Deleted · test · medium · {"product":"azure","service":"activitylogs"}
- Google Cloud Service Account Disabled or Deleted · test · medium · {"product":"gcp","service":"gcp.audit"}
- Okta User Account Locked Out · test · medium · {"product":"okta","service":"okta"}
- Group Has Been Deleted Via Groupdel · test · medium · {"product":"linux","category":"process_creation"}
- User Has Been Deleted Via Userdel · test · medium · {"product":"linux","category":"process_creation"}
- User Logoff Event · test · informational · {"service":"security","product":"windows"}
- Remove Account From Domain Admin Group · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
Atlas deterministic concepts
T1531 Account Access Removal
MATCH(account_disabled_or_deleted OR credential_reset OR role_removed) AND actor NOT_IN approved_identity_admins -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0120 Account Access Removal via Multi-Platform Audit Correlation
AN0334 Analytic 0334
Correlated user account modification (reset, disable, deletion) events with anomalous process lineage (e.g., PowerShell or net.exe from an interactive session), especially outside of IT admin change windows or by non-admin users.
AN0335 Analytic 0335
Password changes or account deletions via 'passwd', 'userdel', or 'chage' preceded by interactive shell or remote command execution from non-privileged accounts.
AN0336 Analytic 0336
Execution of dscl or sysadminctl commands to disable, delete, or modify users combined with anomalous process ancestry or terminal session launch.
AN0337 Analytic 0337
Invocation of esxcli 'system account remove' from vCLI, SSH, or vSphere API with anomalous user access or outside maintenance windows.
AN0338 Analytic 0338
O365 UnifiedAuditLog entries for Remove-Mailbox or Set-Mailbox with account disable or delete actions correlated with suspicious login locations or MFA bypass.
AN0339 Analytic 0339
Deletion or disablement of user accounts in platforms like Okta, Salesforce, or Zoom with anomalies in admin session attributes or mass actions within short duration.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Command Execution · DC0064
- Process Creation · DC0032
- User Account Authentication · DC0002
- User Account Deletion · DC0009
- User Account Modification · DC0010
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.