T1078 Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Win Susp Computer Name Containing Samtheadmincriticaltest · windows
- AWS IAM S3Browser LoginProfile Creationhightest · aws
- AWS IAM S3Browser Templated S3 Bucket Policy Creationhightest · aws
- AWS IAM S3Browser User or AccessKey Creationhightest · aws
- Account Created And Deleted Within A Close Time Framehightest · azure
- Activity From Anonymous IP Addresshightest · azure
- Application AppID Uri Configuration Changeshightest · azure
- Application URI Configuration Changeshightest · azure
- Atypical Travelhightest · azure
- Azure AD Threat Intelligencehightest · azure
- Azure Subscription Permission Elevation Via ActivityLogshightest · azure
- Azure Subscription Permission Elevation Via AuditLogshightest · azure
- Changes To PIM Settingshightest · azure
- External Remote SMB Logon from Public IPhightest · windows
- Impossible Travelhightest · azure
- Invalid PIM Licensehightest · azure
- Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructurehightest · aws
- New Countryhightest · azure
- Okta New Admin Console Behaviourshightest · okta
- OpenCanary - SSH Login Attempthightest · opencanary
- OpenCanary - SSH New Connection Attempthightest · opencanary
- OpenCanary - Telnet Login Attempthightest · opencanary
- PIM Alert Setting Changes To Disabledhightest · azure
- PIM Approvals And Deny Elevationhightest · azure
- Potential MFA Bypass Using Legacy Client Authenticationhightest · azure
Mostrando 25 de 82.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.