Dormant Accounts Becoming Active¶
Hypothesis¶
An attacker is using an account that had gone unused: a former employee, a contractor, a test account, or an old service account. Nobody notices activity on an account nobody watches, and these accounts often have old, weak, or leaked passwords.
ATT&CK¶
Data¶
- Entra ID
SigninLogswith enough retention to see the dormant period (90 days or more) - Domain Controller Security logs (4624) or Active Directory
lastLogonTimestamp
Approach¶
I look for accounts that signed in recently but had no sign-ins for a long period before that.
Cloud accounts active today after 60 or more days without a sign-in:
let recent = SigninLogs
| where TimeGenerated > ago(1d) and ResultType == "0"
| summarize FirstRecent = min(TimeGenerated), IPs = make_set(IPAddress, 10) by UserPrincipalName;
let prior = SigninLogs
| where TimeGenerated between (ago(120d) .. ago(1d)) and ResultType == "0"
| summarize PriorLast = max(TimeGenerated) by UserPrincipalName;
recent
| join kind=leftouter prior on UserPrincipalName
| where isnull(PriorLast) or PriorLast < ago(60d)
| project UserPrincipalName, FirstRecent, PriorLast, IPs
Enabled Active Directory accounts that have not logged on in 90 days, the list to watch and clean up:
Search-ADAccount -AccountInactive -TimeSpan 90.00:00:00 -UsersOnly |
Where-Object Enabled |
Get-ADUser -Properties LastLogonDate, PasswordLastSet, Description |
Select-Object SamAccountName, LastLogonDate, PasswordLastSet, Description
LastLogonDate comes from lastLogonTimestamp, which replicates on a delay of up to about two weeks, so it is fine for finding stale accounts but not for exact last logon times.
What Normal Looks Like¶
- Employees returning from leave
- New hires signing in for the first time (no prior sign-in at all)
- Seasonal or occasional users
Suspicious signs are: an account belonging to someone who has left, a sign-in from an IP or country the account never used before, or a test or shared account that suddenly signs in interactively.
If I Find Something¶
I confirm with HR or the account owner's manager. Unauthorized use goes to the Compromised Account / BEC playbook. Either way, the hunt usually ends with a list of accounts to disable, and a gap in the offboarding process to fix.