Detection rules › By eventMicrosoft-Windows-Security-Auditing event 47263 detection rules reference this event. View event page.Splunk (3)Short Lived Windows Accounts T1078.003, T1136.001 Windows Increase in User Modification Activity T1098, T1562 Windows Multiple Accounts Deleted T1078, T1098