T1021.007 Cloud Services
Subtécnica de T1021 Remote Services
Adversaries may log into accessible cloud services within a compromised environment using [Valid Accounts](https://attack.mitre.org/techniques/T1078) that are synchronized with or federated to on-premises user identities. The adversary may then perform management actions or access cloud-hosted resources as the logged-on user. Many enterprises federate centrally managed user identities to cloud…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- AWS Console GetSigninToken Potential Abusemediumtest · aws
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.