Skip to content

T1531: Account Access Removal

T1531: Account Access Removal

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....

View on MITRE ATT&CK →

AWS DeleteUser

Deletes an IAM user after dependent credentials and associations are removed.

Cloud Service: AWS - IAM
Tactics:
Techniques: