User Account Control (UAC) Setting Change

This rule detects changes to a user account's User Account Control (UAC) settings, specifically when the 'NewUacValue' is set to '0x2080'. This value corresponds to the 'ACCOUNTDISABLE' flag, indicating that a user account has been disabled. Monitoring such changes can help identify potential malicious activity where an attacker might disable legitimate user accounts to disrupt operations or hinder incident response.