T1098 Account Manipulation — ATT&CK Technique
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials. In order to create or manipulate accounts, the adversary must already have sufficient permissions on systems or the domain. However, account manipulation may also lead to privilege escalation where modifications grant access to additional roles, permissions, or higher-privileged Valid Accounts.
Detection coverage (50)
- Suspicious Computer Account Name Change CVE-2021-42287 high
- New MsDS-DelegatedManagedServiceAccount (DMSA) Object Created medium
- msDS-ManagedAccountPrecededByLink Attribute Modified medium
- Cisco Local Accounts high
- Bitbucket Global Permission Changed medium
- AWS IAM Backdoor Users Keys medium
- AWS Route 53 Domain Transfer Lock Disabled low
- AWS User Login Profile Was Modified high
- AWS Route 53 Domain Transferred to Another Account low
- Number Of Resource Creation Or Deployment Activities medium
- Change to Authentication Method medium
- Bulk Deletion Changes To Privileged Account Permissions high
- Anomalous User Activity high
- GCP Access Policy Deleted medium
- Google Workspace Granted Domain API Access medium
- Google Workspace User Granted Admin Privileges medium
- Privileged User Has Been Created high
- ESXi Admin Permission Assigned To Account Via ESXCLI high
- A Member Was Removed From a Security-Enabled Global Group low
- A Member Was Added to a Security-Enabled Global Group low
- A Security-Enabled Global Group Was Deleted low
- Powerview Add-DomainObjectAcl DCSync AD Extend Right high
- Active Directory User Backdoors high
- Enabled User Right in AD to Control User Objects high
- A New Trust Was Created To A Domain medium
- Password Change on Directory Service Restore Mode (DSRM) Account high
- User Added to Local Administrator Group medium
- DMSA Service Account Created in Specific OUs - PowerShell medium
- DMSA Link Attributes Modified low
- Powershell LocalAccount Manipulation medium
- New DMSA Service Account Created in Specific OUs medium
- User Added to Local Administrators Group medium
- User Added To Highly Privileged Group high
- Password Set to Never Expire via WMI medium
- Cisco ASA - User Privilege Level Change
- ESXi Account Modified
- ESXi User Granted Admin Role
- ASL AWS IAM Delete Policy
- ASL AWS IAM Failure Group Deletion
- ASL AWS IAM Successful Group Deletion
- AWS IAM Delete Policy
- AWS IAM Failure Group Deletion
- AWS IAM Successful Group Deletion
- Azure AD Service Principal Owner Added
- Azure AD User Enabled And Password Reset
- Azure AD User ImmutableId Attribute Updated
- O365 Application Registration Owner Added
- Windows AD Privileged Group Modification
- Windows AD add Self to Group
- Windows AD DSRM Account Changes