LoginFromDisabledAccount Pending

0% Complete
0% Completion    00:00:00
Initial Analysis 0/17 Remediation 0/8
Identify source username trying to login
Identify application/destination address it is trying to login
Check AD to which the account is authenticating to
Identify from where the user is logging in
Identify the source user details
Identify last login time observed from this user
Identify reason why account disabled
Check if login is successful login or a failed attempt
Identify logon type - interactive login or network login etc.
If login attempt is failed login attempt - identify the error code noticed and reason captured
From last 7 days logs, identify when user was disabled , post the account was disabled was the account was enabled back. Account disabled - windows logs (event ID 4725) and account enabled - windows logs(event id 4722)
If above steps events seen - identify User who has disabled/enabled. Check if user has elevated any privileges
From the last 24 hour logs identify if the disabled account has any password reset attempts or any password never set to expire enabled
From the last 24 hour logs, identify if there are any Phishing emails or spam email received by user and if any attachments downloaded
From the last 24 hour logs, identify if there are any suspicious process running
From the last 24 hour logs, identify if there are any unwanted software installations noticed
From the last 24 hour logs identify if there are any AV infections noticed
If user is on long vacation and returned - alert as false positive
Check reason why user account is disabled and the reason for these login attempts
If user is not part of organisation - recommended to delete user account
If the user is still a part of organization, and if any phishing or spam emails are detected - recommended to block the sender email address on the email gateway
If any unwanted software installation noticed - recommended to delete the unwanted software
If any suspicious process detected - recommended to kill the process
If AV infections noticed - run a full AV scan
Good practise - monthly review of all disabled accounts and delete the unwanted or unused accounts