T1078 Valid Accounts — ATT&CK Technique
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence. In some cases, adversaries may abuse inactive accounts: for example, those belonging to individuals who are no longer part of an organization. Using these accounts may allow the adversary to evade detection, as the original account user will not be present to identify any anomalous activity taking place on their account. The overlap of permissions for local, domain, and cloud accounts across a network of systems is of concern because the adversary may be able to pivot across accounts and systems to reach a high level of access (i.e., domain or enterprise administrator) to bypass access controls set within the enterprise.
Detection coverage (50)
- Privilege Role Sign-In Outside Expected Controls high
- Interactive Logon to Server Systems medium
- Privilege Role Sign-In Outside Of Normal Hours high
- Account Created And Deleted By Non Approved Users medium
- Authentication Occuring Outside Normal Business Hours low
- Privilege Role Elevation Not Occuring on SAW or PAW high
- Root Account Enable Via Dsenableroot medium
- Kubernetes Admission Controller Modification medium
- OpenCanary - SSH Login Attempt high
- OpenCanary - SSH New Connection Attempt high
- OpenCanary - Telnet Login Attempt high
- Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure high
- AWS Key Pair Import Activity medium
- AWS Suspicious SAML Activity medium
- Azure Kubernetes Admission Controller medium
- Account Created And Deleted Within A Close Time Frame high
- Azure Domain Federation Settings Modified medium
- Cisco BGP Authentication Failures low
- PIM Alert Setting Changes To Disabled high
- Azure Subscription Permission Elevation Via AuditLogs high
- Unfamiliar Sign-In Properties high
- Atypical Travel high
- Stale Accounts In A Privileged Role high
- Impossible Travel high
- Suspicious Browser Activity high
- Invalid PIM License high
- Azure AD Threat Intelligence high
- Activity From Anonymous IP Address high
- New Country high
- Roles Assigned Outside PIM high
- Roles Activated Too Frequently high
- Roles Activation Doesn't Require MFA high
- Roles Are Not Being Used high
- Too Many Global Admins high
- Increased Failed Authentications Of Any Type medium
- Measurable Increase Of Successful Authentications low
- Suspicious SignIns From A Non Registered Device high
- Application Using Device Code Authentication Flow medium
- Applications That Are Using ROPC Authentication Flow medium
- Azure Unusual Authentication Interruption medium
- Google Cloud Kubernetes Admission Controller medium
- Google Workspace Government Attack Warning medium
- Azure Login Bypassing Conditional Access Policies high
- Microsoft 365 - Impossible Travel Activity medium
- Logon from a Risky IP Address medium
- Guest Account Enabled Via Sysadminctl low
- Cisco LDP Authentication Failures low
- Huawei BGP Authentication Failures low
- Juniper BGP Missing MD5 low
- Failed Logon From Public IP medium
Malware using this technique
Threat actors using this technique
- Muddled Libra
- FIN10
- APT33
- Anubis
- INC Ransom
- FIN6
- Fox Kitten
- APT41
- FIN8
- FIN4
- FIN7
- Scattered Spider
- Dragonfly
- GALLIUM
- APT18
- POLONIUM
- Void Manticore
- Volt Typhoon
- Lazarus Group
- Chimera
- FIN5
- APT10
- Sandworm Team
- Cinnamon Tempest
- Akira
- LAPSUS$
- Carbanak
- APT28
- APT27
- Suckfly
- Play Ransomware
- Axiom
- Evil Corp
- APT40
- Silence
- OilRig
- Silent Librarian
- Conti
- APT29
- UNC3886
- BlackByte
- Sea Turtle
- Star Blizzard
- APT39
- Medusa Ransomware
- APT24
- APT15