T1021.007 Cloud Services
Sub-technique of T1021 Remote Services
Adversaries may log into accessible cloud services within a compromised environment using [Valid Accounts](https://attack.mitre.org/techniques/T1078) that are synchronized with or federated to on-premises user identities. The adversary may then perform management actions or access cloud-hosted resources as the logged-on user. Many enterprises federate centrally managed user identities to cloud…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- AWS Console GetSigninToken Potential Abusemediumtest · aws
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.