T1078.002 Domain Accounts
Sub-technique of T1078 Valid Accounts
Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.(Citation: TechNet Credential Theft) Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users,…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructurehightest · aws
- DMSA Service Account Created in Specific OUs - PowerShellmediumexperimental · windows
- New DMSA Service Account Created in Specific OUsmediumexperimental · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.