Suspicious Account Activity

Description

This anomaly contains multiple detection methods that look at account events for suspcious activity (e.g., activity by an expired user). Check the associated detection methods for an exhaustive list of what triggers this anomaly.

Content Mapping

This content is not mapped to any local saved search. Add mapping


Use Case

Advanced Threat Detection, Security Monitoring, Insider Threat

Category

Account Compromise, IAM Analytics, Zero Trust

Alert Volume

Medium

Journey

Stage 6

MITRE ATT&CK Tactics

Persistence
Initial Access
Privilege Escalation

MITRE ATT&CK Techniques

Create Account
Valid Accounts

MITRE Threat Groups

APT18
APT28
APT33
APT39
APT41
Carbanak
Chimera
Dragonfly 2.0
FIN10
FIN4
FIN5
FIN6
FIN8
Leviathan
Night Dragon
OilRig
PittyTiger
Sandworm Team
Silence
Soft Cell
Suckfly
TEMP.Veles
Threat Group-3390
UNC2452
Wizard Spider
menuPass

Data Sources

Windows Security
Email
Authentication