T1098 Account Manipulation
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups.(Citation: FireEye SMOKEDHAM June 2021) These actions could also include account activity designed to subvert security policies, such as…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Password Change on Directory Service Restore Mode (DSRM) Accounthighstable · windows
- AWS User Login Profile Was Modifiedhightest · aws
- Active Directory User Backdoorshightest · windows
- Added Credentials to Existing Applicationhightest · azure
- Anomalous User Activityhightest · azure
- App Granted Privileged Delegated Or App Permissionshightest · azure
- Bulk Deletion Changes To Privileged Account Permissionshightest · azure
- Cisco Local Accountshightest · cisco
- ESXi Admin Permission Assigned To Account Via ESXCLIhightest · linux
- Enabled User Right in AD to Control User Objectshightest · windows
- Powerview Add-DomainObjectAcl DCSync AD Extend Righthightest · windows
- Privileged User Has Been Createdhightest · linux
- Suspicious Computer Account Name Change CVE-2021-42287hightest · windows
- User Added To Highly Privileged Grouphightest · windows
- Windows LAPS Credential Dump From Entra IDhightest · azure
- A New Trust Was Created To A Domainmediumstable · windows
- User Added to Local Administrator Groupmediumstable · windows
- AWS IAM Backdoor Users Keysmediumtest · aws
- App Assigned To Azure RBAC/Microsoft Entra Rolemediumtest · azure
- Bitbucket Global Permission Changedmediumtest · bitbucket
- Change to Authentication Methodmediumtest · azure
- GCP Access Policy Deletedmediumtest · gcp
- Github Outside Collaborator Detectedmediumtest · github
- Google Workspace Application Access Level Modifiedmediumtest · gcp
- Google Workspace Granted Domain API Accessmediumtest · gcp
Showing 25 of 36.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.