Account Access Removal
Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts.(Citation: Obsidian Security SaaS Ransomware June 2023) Adversaries may also subsequently log off and/or perform a [System Shutdown/Reboot](https://attack.mitre.org/techniques/T1529) to set malicious chan...
BY SOURCE
PROCEDURES (16)
Auto-extracted: 6 detections for general monitoring
Auto-extracted: 4 detections for cloud
Auto-extracted: 2 detections for authentication monitoring
Auto-extracted: 2 detections for process creation monitoring
Auto-extracted: 2 detections for credential
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for privilege
Auto-extracted: 1 detections for cloud
Auto-extracted: 1 detections for api
Auto-extracted: 1 detections for script execution monitoring
Auto-extracted: 1 detections for cloud monitoring
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for aws
Auto-extracted: 1 detections for privilege
Auto-extracted: 1 detections for aws
Auto-extracted: 1 detections for api