Tag
low
advisory
Spike in User Account Management Events
5 TTPsElastic Security's machine learning rule detects an unusual spike in Windows user account management events, including account creation, modification, or deletion, indicating potential privilege escalation or unauthorized activity by an adversary.
Privileged Access Detection integration +7
privileged-access-detection
machine-learning
anomaly-detection
windows
account-management
privilege-escalation
persistence
5t
updated
high
advisory
ESXi Account Modification Detection
2 rules 7 TTPsDetection of local user account creation, deletion, or modification on an ESXi host, potentially indicating unauthorized access, persistence attempts, or defense evasion.
ESXi
vmware
account-management
persistence
privilege-escalation
2r
7t