Anomalous user account change
Last updated on:
In this page
About the rule
Rule Type
Advanced
Rule Description
A user account is created and deleted within a short window of time.
Severity
Critical
Rule Requirement
Criteria
Action1: actionname = "account_created" Action2: actionname = "null" AND HOSTTYPE = Action1.HOSTTYPE AND TARGETUSER = Action1.TARGETUSER sequence:Action1 followedby Action2 within 60m select Action1.HOSTNAME,Action1.MESSAGE,Action1.HOSTTYPE,Action1.USERNAME,Action1.TARGETUSER,
Detection
Execution Mode
realtime
Log Sources
Miscellaneous


