Cross-source coverage
T1078.004 / ATT&CK
Valid Accounts: Cloud Accounts
283 rules across 8 sources.
From MITRE ATT&CK 19.2
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Service or user accounts may be targeted by adversaries through Brute Force, Phishing, or various other means to gain access to the environment. Federated or synced accounts may be a pathway for the adversary to affect both on-premises systems and cloud environments - for example, by leveraging shared credentials to log onto Remote Services. High privileged cloud accounts, whether federated, synced, or cloud-only, may also allow pivoting to on-premises environments by leveraging SaaS-based Software Deployment Tools to run commands on hybrid-joined devices.
An adversary may create long lasting Additional Cloud Credentials on a compromised cloud account to maintain persistence in the environment. Such credentials may also be used to bypass security controls such as multi-factor authentication.
Cloud accounts may also be able to assume Temporary Elevated Cloud Access or other privileges through various means within the environment. Misconfigurations in role assignments or role assumption policies may allow an adversary to use these mechanisms to leverage permissions outside the intended scope of the account. Such over privileged accounts may be used to harvest sensitive data from online storage accounts and databases through Cloud API or other methods. For example, in Azure environments, adversaries may target Azure Managed Identities, which allow associated Azure resources to request access tokens. By compromising a resource with an attached Managed Identity, such as an Azure VM, adversaries may be able to Steal Application Access Tokens to move laterally across the cloud environment.
- Tactics
- Stealth · Persistence · Privilege Escalation · Initial Access
- Platforms
- IaaS · Identity Provider · Office Suite · SaaS
- Telemetry
-
azure:signinlogssaas:oktaAWS:CloudTrailgcp:auditm365:unifiedm365:signinlogs
How MITRE says to detect it DET0546
Detection of Abused or Compromised Cloud Accounts for Access and Persistence
Identity Provider Analytic 1503
Detects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts.
azure:signinlogsSign-in activitysaas:oktauser.authentication.sso
IaaS Analytic 1504
Detects cloud account use for API calls that exceed normal scope, such as IAM changes or access to services never used before.
AWS:CloudTrailConsoleLogin, AssumeRole, ListAccessKeys, CreateUsergcp:auditadmin.googleapis.com
SaaS Analytic 1505
Detects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users.
m365:unifiedFileAccessed, SharingSetgcp:auditdrive.activity
Office Suite Analytic 1506
Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles.
m365:signinlogsUserLogingcp:auditlogin.event
elastic/detection-rules
123 rules| Detection | Severity | Format |
|---|---|---|
| Entra ID Protection Admin Confirmed Compromise | Critical | Elastic TOML |
| AWS AssumeRoleWithWebIdentity from Kubernetes SA and External ASN | High | Elastic TOML |
| AWS Bedrock AgentCore Execution Role Used Outside Its Runtime | High | Elastic TOML |
| AWS Bedrock API Key Phantom User Activity Outside Bedrock | High | Elastic TOML |
| AWS Bedrock Foundation Model Enumeration Followed by Invocation via Long-Term Key | High | Elastic TOML |
| AWS CloudShell Environment Created | High | Elastic TOML |
| AWS Credentials Used from GitHub Actions and Non-CI/CD Infrastructure | High | Elastic TOML |
| AWS EC2 Instance Console Login via Assumed Role | High | Elastic TOML |
| AWS EC2 Instance Profile Associated with Running Instance | High | Elastic TOML |
| AWS IAM API Calls via Temporary Session Tokens | High | Elastic TOML |
+ 113 more from elastic/detection-rules → showing the 10 highest-severity
Azure/Azure-Sentinel
45 rules| Detection | Severity | Format |
|---|---|---|
| Addition of a Temporary Access Pass to a Privileged Account | High | KQL |
| Changes to PIM Settings | High | KQL |
| URL Added to Application from Unknown Domain | High | KQL |
| Application ID URI Changed | Medium | KQL |
| Application Redirect URL Update | Medium | KQL |
| Authentication Attempt from New Country | Medium | KQL |
| Authentications of Privileged Accounts Outside of Expected Controls | Medium | KQL |
| Changes to Application Ownership | Medium | KQL |
| Conditional Access Policy Modified by New User | Medium | KQL |
| End-user consent stopped due to risk-based consent | Medium | KQL |
+ 35 more from Azure/Azure-Sentinel → showing the 10 highest-severity
SigmaHQ/sigma
41 rules| Detection | Severity | Format |
|---|---|---|
| Application AppID Uri Configuration Changes | High | Sigma |
| Application URI Configuration Changes | High | Sigma |
| AWS IAM S3Browser LoginProfile Creation | High | Sigma |
| AWS IAM S3Browser Templated S3 Bucket Policy Creation | High | Sigma |
| AWS IAM S3Browser User or AccessKey Creation | High | Sigma |
| Azure Subscription Permission Elevation Via ActivityLogs | High | Sigma |
| Changes To PIM Settings | High | Sigma |
| Okta New Admin Console Behaviours | High | Sigma |
| PIM Approvals And Deny Elevation | High | Sigma |
| Potential MFA Bypass Using Legacy Client Authentication | High | Sigma |
+ 31 more from SigmaHQ/sigma → showing the 10 highest-severity
panther-labs/panther-analysis
27 rules| Detection | Severity | Format |
|---|---|---|
| Kubernetes System Role Modified or Deleted | Critical | Panther Python |
| Slack Primary Owner Transferred | Critical | Panther Python |
| AWS Compromised IAM Key Quarantine | High | Panther Python |
| AWS IMDS Credential Usage Outside Expected Services | High | Panther Python |
| Azure Protection Multiple Alerts for User | High | Panther Python |
| GAIA GCPW Credential Theft Attack Chain | High | Panther Python |
| Kubernetes Role With Node Proxy Permissions Created | High | Panther Python |
| Kubernetes Role With Pod Exec Permissions Created | High | Panther Python |
| Kubernetes Role With Wildcard Permissions Created | High | Panther Python |
| Kubernetes Service Account Token Theft from Pod | High | Panther Python |
+ 17 more from panther-labs/panther-analysis → showing the 10 highest-severity
splunk/security_content
20 rules| Detection | Severity | Format |
|---|---|---|
| ASL AWS Create Policy Version to allow all resources | Undefined | SPL |
| AWS Create Policy Version to allow all resources | Undefined | SPL |
| AWS SetDefaultPolicyVersion | Undefined | SPL |
| AWS Successful Single-Factor Authentication | Undefined | SPL |
| Azure AD Authentication Failed During MFA Challenge | Undefined | SPL |
| Azure AD Multiple Failed MFA Requests For User | Undefined | SPL |
| Azure AD Service Principal Authentication | Undefined | SPL |
| Azure AD Successful PowerShell Authentication | Undefined | SPL |
| Azure AD Successful Single-Factor Authentication | Undefined | SPL |
| Azure Runbook Webhook Created | Undefined | SPL |
+ 10 more from splunk/security_content → showing the 10 highest-severity
chronicle/detection-rules
16 rules| Detection | Severity | Format |
|---|---|---|
| aws_api_call_outside_of_organization | High | YARA-L |
| aws_iam_administrator_access_policy_attached | High | YARA-L |
| gcp_workload_identity_pool_disabled_or_deleted | High | YARA-L |
| o365_admin_login_activity_to_uncommon_mscloud_apps | High | YARA-L |
| onelogin_super_user_privileges_assigned | High | YARA-L |
| aws_user_creates_permanent_access_key | Medium | YARA-L |
| entra_id_admin_login_activity_to_uncommon_mscloud_apps | Medium | YARA-L |
| gcp_kms_decryption_by_unexpected_service_account | Medium | YARA-L |
| google_workspace_external_user_added_to_group | Medium | YARA-L |
| google_workspace_user_unsuspended | Medium | YARA-L |
+ 6 more from chronicle/detection-rules → showing the 10 highest-severity
Wazuh Core Ruleset
6 rulesBert-JanP/Hunting-Queries-Detection-Rules
5 rules| Detection | Severity | Format |
|---|---|---|
| CA Application SignIn Failures | Undefined | KQL |
| CA User SignIn Failures | Undefined | KQL |
| Cloud Persistence Activities by User At Risk | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
| New Authentication App Detected | Undefined | KQL |