ITM is an open framework - Submit your contributions now.

Insider Threat Matrix™

  • ID: DT015
  • Created: 30th May 2024
  • Updated: 14th June 2024
  • Platform: Windows
  • Contributor: The ITM Team

Windows Local Account Deleted

A subject may delete a local Windows user account to delete files associated with this user.

Event ID 4726 in Windows Security logs is called "User Account Deleted." This event is logged when a user account is deleted from the local system.

This may represent an anti-forensics technique if there is no reasonable explanation for why the user was deleted from the system.