Anomalous user account change
Last updated on:
In this page
About the rule
Rule Type
Advanced
Rule Description
A user account is created and deleted within a short window of time.
Severity
Critical
Rule Requirement
Criteria
Action1:
actionname = "Account created"
Action2:
actionname = "Account deleted" AND HOSTTYPE = Action1.HOSTTYPE AND TARGETUSER = Action1.TARGETUSER
sequence:Action1 followedby Action2 within 60m
select Action1.HOSTNAME,Action1.MESSAGE,Action1.HOSTTYPE,Action1.USERNAME,Action1.TARGETUSER,Action2.HOSTNAME,Action2.MESSAGE,Action2.HOSTTYPE,Action2.USERNAME,Action2.TARGETUSER
Detection
Execution Mode
realtime
Log Sources
Miscellaneous


