• Skip to primary navigation
  • Skip to content
  • Skip to footer
Security Content Security Content
  • Detections
  • Analytic Stories
  • Playbooks
  • Blog
  • About
    • Type
      • Investigation
      • Response
    • Use Case
      • Endpoint
      • Enrichment
      • Phishing
    • D3fend Technique Category
      • Credential Eviction
      • File Analysis
      • Identifier Analysis
      • Network Isolation
    • Soar App
      • AD LDAP
      • AWS IAM
      • Azure AD Graph
      • Carbon Black Response
      • Cisco Umbrella
      • CrowdStrike OAuth API
      • Cylance
      • Falcon Host API
      • G Suite for GMail
      • Jira
      • LDAP
      • Palo Alto Networks Firewall
      • Panorama
      • Phantom
      • PhishTank
      • Reversing Labs
      • SMTP
      • SSH
      • ServiceNow
      • Splunk
      • Splunk Attack Analyzer Connector for Splunk SOAR
      • Threat Grid
      • TruSTAR
      • VirusTotal
      • VirusTotal v3
      • WildFire
      • Windows Defender ATP
      • Windows Remote Management
      • Zscaler
      • aws_iam
      • azure_ad_graph
      • microsoft_ad_ldap
      • urlscan.io

    Credential Eviction

    Name SOAR App D3FEND Use Case
    AD LDAP Account Locking AD LDAP Account Locking Phishing, Endpoint
    AWS IAM Account Locking AWS IAM Account Locking Phishing, Endpoint
    Active Directory Disable Account Dispatch AD LDAP, Azure AD Graph Account Locking Phishing, Endpoint
    Azure AD Locking Account Azure AD Graph Account Locking Phishing, Endpoint
    • Twitter
    • GitHub
    • Feed
    © 2023 Splunk Threat Research Team (STRT). Powered by Jekyll & Minimal Mistakes.