Navigation :
Activity from Expired User Identity
Description
Alerts when an event is discovered from a user associated with identity that is now expired (that is, the end date of the identity has been passed).
Content Mapping
This content is not mapped to any local saved search. Add mapping
Use Case
Insider Threat, Security Monitoring
Category
Insider Threat
Alert Volume
Alerts when an event is discovered from a user associated with identity that is now expired (that is, the end date of the identity has been passed).
SPL Difficulty
Medium
Journey
Stage 2
MITRE ATT&CK Tactics
Initial Access
Persistence
MITRE ATT&CK Techniques
Valid Accounts
MITRE Threat Groups
APT18
APT28
APT33
APT39
APT41
Carbanak
Chimera
Dragonfly 2.0
FIN10
FIN4
FIN5
FIN6
FIN8
Leviathan
Night Dragon
OilRig
PittyTiger
Sandworm Team
Silence
Soft Cell
Suckfly
TEMP.Veles
Threat Group-3390
Wizard Spider
menuPass
Data Sources
Authentication