LoFP LoFP / t1078.003

t1078.003

TitleTags
it is possible that a legitimate user is experiencing an issue causing multiple account login failures leading to lockouts.
it is possible that an administrator created and deleted an account in a short time period. verifying activity with an administrator is advised.
legitimate account creation occurs during employee onboarding, contractor provisioning, service account setup, or emergency access. verify against hr records and change management tickets. filter known admin accounts during business hours.
legitimate administration activities
legitimate changes occur during role changes, temporary escalation for maintenance, or security policy adjustments. verify against change management. filter known admin accounts during maintenance windows.
unknown
valid usernames with high entropy or source/destination system pairs with multiple authenticating users will make it difficult to identify the real user authenticating.