Applied Cybernetics Group
T1531 — Account Access Removal
- Technique
T1531- Tactics
- Impact
- MISP citations
- 0
- KEV CVEs mapped
- 1
- Community rules
- 9
- thrunt rules
- 0
- Upstream
- https://attack.mitre.org/techniques/T1531
MITRE description
Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts.(Citation: Obsidian Security SaaS Ransomware June 2023) Adversaries may also subsequently log off and/or perform a [System Shutdown/Reboot](https://attack.mitre.org/techniques/T1529) to set malicious changes into place.(Citation: CarbonBlack LockerGoga 2019)(Citation: Unit42 LockerGoga 2019) In Windows, [Net](https://attack.mitre.org/software/S0039) utility, <code>Set-LocalUser</code> and <code>Set-ADAccountPassword</code> [PowerShell](https://attack.mitre.org/techniques/T1059/001) cmdlets may be used by adversaries to modify user accounts. Accounts could also be disabled by Group Policy. In Linux, the <code>passwd</code> utility may be used to change passwords. On ESXi servers, accounts can be removed or modified via esxcli (`system account set`, `system account remove`). Adversaries who use ransomware or similar attacks may first perform this and other Impact behaviors, such as [Data Destruction](https://attack.mitre.org/techniques/T1485) and [Defacement](https://attack.mitre.org/techniques/T1491), in order to impede incident response/recovery before completing the [Data Encrypted for Impact](https://attack.mitre.org/techniques/T1486) objective.
KEV CVEs mapped to this technique
Per MITRE CTID's hand-curated KEV→ATT&CK mappings — these are the actively-exploited vulnerabilities behind this technique's KEV signal.
Detection coverage
SigmaHQ community rules
- AWS SAML Provider Deletion Activity (core)
- AWS ElastiCache Security Group Modified or Deleted (core)
- Azure Kubernetes Service Account Modified or Deleted (core)
- Google Cloud Service Account Disabled or Deleted (core)
- Okta User Account Locked Out (core)
- Group Has Been Deleted Via Groupdel (core)
- User Has Been Deleted Via Userdel (core)
- User Logoff Event (core)
- Remove Account From Domain Admin Group (core)