{
  "technique_id": "T1531",
  "name": "Account Access Removal",
  "tactics": [
    "Impact"
  ],
  "platforms": [
    "Linux",
    "macOS",
    "Windows",
    "SaaS",
    "IaaS",
    "Office Suite",
    "ESXi"
  ],
  "summary": "Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a [System Shutdown/Reboot](https://attack.mitre.org/techniques/T1529) to set malicious changes into place...",
  "generated_by": "SOC Response Atlas by Basyrix"
}