User account deleted via Net command
Last updated on:
In this page
Rule name | Rule type | Log sources | MITRE ATT&CK tags | Severity |
|---|---|---|---|---|
User account deleted via Net command | Standard | Windows | Impact: Account Access Removal (T1531) | Trouble |
About the rule
Rule Type
Standard
Rule Description
Detects deletion of a user account using the net command.
Why this rule?
User account deletion via net.exe command represents either legitimate de-provisioning activities or malicious actions by attackers seeking to cover their tracks, eliminate evidence of compromised accounts, disrupt operations by removing critical service or administrative accounts, or execute destructive attacks as part of ransomware or wiper malware campaigns where account deletion maximizes recovery difficulty and operational impact.
Severity
Trouble
Rule journey
Attack chain scenario
Impact → Net Command Execution → User Account Deletion → Access Removal → Service Disruption.
Impact
Unauthorized account deletion can disrupt operations, remove legitimate user access, and cover attacker tracks by eliminating evidence.
Rule Requirement
Prerequisites
Enable process creation monitoring (Event ID 1 or 4688).
Criteria
Action1: actionname = "Process started" AND (( PROCESSNAME endswith "net.exe,net1.exe" OR ORIGINALFILENAME = "net.exe,net1.exe" ) AND ( COMMANDLINE contains "user" AND COMMANDLINE contains "/delete" )) select Action1.HOSTNAME,Action1.MESSAGE,Action1.COMMANDLINE,Action1.FILE_NAME,Action1.PROCESSNAME,Action1.USERNAME,Action1.PARENTPROCESSNAME,Action1.PARENTPROCESSCOMMANDLINE,Action1.ORIGINALFILENAME,Action1.PARENTPROCESSID,Action1.PROCESSID,Action1.PRODUCT_NAME,Action1.SECURITYID,Action1.DOMAIN
Detection
Execution Mode
realtime
Log Sources
Windows
MITRE ATT&CK
Impact: Account Access Removal (T1531)
Future actions
Known False Positives
Normal user de-provisioning activities, automated account lifecycle management scripts, or IT support operations removing stale accounts.
Next Steps
- Identification: Identify the deleted user account and the user who performed the deletion.
- Analysis: Determine if the account deletion was authorized or part of legitimate de-provisioning.
- Response: Restore accidentally deleted accounts if necessary, investigate potential malicious activity or impact operations.


