heroui logo

Identify New User Accounts

Splunk Security Content

View Source
Summary
The 'Identify New User Accounts' detection rule is designed to help organizations profile newly created user accounts within their environment. This rule focuses on identifying accounts that have been added to the network in the past week. The search leverages the Splunk data model 'Identity_Management' to retrieve identities and evaluates the creation date of an account against the current date to determine if it falls within the one-week time frame. By using specific evaluations and filtering, this rule provides insights into potential security concerns regarding unauthorized user account creation, which is vital for maintaining the integrity of an organization's access control policies. As the rule is currently deprecated, users should consider updating or replacing it with newer rules to ensure accurate threat detection.
Categories
  • Identity Management
Data Sources
  • User Account
ATT&CK Techniques
  • T1078.002
Created: 2024-11-14