Disabled User Monitoring For On-Prem
This rule detects Windows Security Event ID 4725, which indicates that a user account has been disabled. It extracts relevant details such as the target user account, domain, and the user who performed the action to provide context for potential account-based denial-of-service or unauthorized access removal attempts.
Cortex XDR

