Detection rules › Kusto Query Language
User account created and deleted within 10 mins
'Identifies when a user account is created and then deleted within 10 minutes. This can be an indication of compromise and an adversary attempting to hide in the noise.'
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Initial Access | T1078 Valid Accounts |
| Persistence | T1078 Valid Accounts, T1098 Account Manipulation |
| Privilege Escalation | T1078 Valid Accounts, T1098 Account Manipulation |
| Defense Evasion | T1078 Valid Accounts |
Event coverage
| Provider | Event ID | Title |
|---|---|---|
| Security-Auditing | 4720 | A user account was created. |
| Security-Auditing | 4726 | A user account was deleted. |
Stages and Predicates
Stage 1: source
<union>
Stage 2: union
union of 2 branches
Stage 3: join
Stage 4: where
macro "((deletionTime - creationTime) < spanoftime)"
Stage 5: extend
Stage 6: where
macro "(tolong(TimeDelta) >= threshold)"