Skip to content

Hide Navigation Hide TOC

Remove Account From Domain Admin Group (48a45d45-8112-416b-8a67-46e03a4b2107)

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts.

Cluster A Galaxy A Cluster B Galaxy B Level
Account Access Removal - T1531 (b24e2a20-3b3d-4bf0-823b-1ed765398fb0) Attack Pattern Remove Account From Domain Admin Group (48a45d45-8112-416b-8a67-46e03a4b2107) Sigma-Rules 1