1200KM / simulation
T1531 Account Access Removal — Attack Simulation
Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place. In Windows, Net utility,…
Technique description
Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place. In Windows, Net utility,…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Change User Password - Windows
Procedure 1b99ef28-f83c-4ec5-8a08-1a56263a5bb2; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Change User Password via passwd
Procedure 3c717bf3-2ecc-4d79-8ac8-0bfbf08fbce6; elevation required; cleanup not declared. Not executed or individually validated.
- Remove Account From Domain Admin Group
Procedure 43f71395-6c37-498e-ab17-897d814a0947; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Delete User via dscl utility
Procedure 4d938c43-2fe8-4d70-a5b3-5bf239aa7846; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Delete User via sysadminctl utility
Procedure d3812c4e-30ee-466a-a0aa-07e355b561d6; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Delete User - Windows
Procedure f21a1d7d-a62f-442a-8c3a-2440d43b19e5; elevation required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.