Cross-source coverage

T1078.004 / ATT&CK

Valid Accounts: Cloud Accounts

283 rules across 8 sources.

From MITRE ATT&CK 19.2

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Service or user accounts may be targeted by adversaries through Brute Force, Phishing, or various other means to gain access to the environment. Federated or synced accounts may be a pathway for the adversary to affect both on-premises systems and cloud environments - for example, by leveraging shared credentials to log onto Remote Services. High privileged cloud accounts, whether federated, synced, or cloud-only, may also allow pivoting to on-premises environments by leveraging SaaS-based Software Deployment Tools to run commands on hybrid-joined devices.

An adversary may create long lasting Additional Cloud Credentials on a compromised cloud account to maintain persistence in the environment. Such credentials may also be used to bypass security controls such as multi-factor authentication.

Cloud accounts may also be able to assume Temporary Elevated Cloud Access or other privileges through various means within the environment. Misconfigurations in role assignments or role assumption policies may allow an adversary to use these mechanisms to leverage permissions outside the intended scope of the account. Such over privileged accounts may be used to harvest sensitive data from online storage accounts and databases through Cloud API or other methods. For example, in Azure environments, adversaries may target Azure Managed Identities, which allow associated Azure resources to request access tokens. By compromising a resource with an attached Managed Identity, such as an Azure VM, adversaries may be able to Steal Application Access Tokens to move laterally across the cloud environment.

Platforms
IaaS · Identity Provider · Office Suite · SaaS
Telemetry
azure:signinlogssaas:oktaAWS:CloudTrailgcp:auditm365:unifiedm365:signinlogs

How MITRE says to detect it DET0546

Detection of Abused or Compromised Cloud Accounts for Access and Persistence

Identity Provider Analytic 1503

Detects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts.

  • azure:signinlogs Sign-in activity
  • saas:okta user.authentication.sso

IaaS Analytic 1504

Detects cloud account use for API calls that exceed normal scope, such as IAM changes or access to services never used before.

  • AWS:CloudTrail ConsoleLogin, AssumeRole, ListAccessKeys, CreateUser
  • gcp:audit admin.googleapis.com

SaaS Analytic 1505

Detects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users.

  • m365:unified FileAccessed, SharingSet
  • gcp:audit drive.activity

Office Suite Analytic 1506

Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles.

  • m365:signinlogs UserLogin
  • gcp:audit login.event

elastic/detection-rules

123 rules
Detection Severity Format
Entra ID Protection Admin Confirmed Compromise Critical Elastic TOML
AWS AssumeRoleWithWebIdentity from Kubernetes SA and External ASN High Elastic TOML
AWS Bedrock AgentCore Execution Role Used Outside Its Runtime High Elastic TOML
AWS Bedrock API Key Phantom User Activity Outside Bedrock High Elastic TOML
AWS Bedrock Foundation Model Enumeration Followed by Invocation via Long-Term Key High Elastic TOML
AWS CloudShell Environment Created High Elastic TOML
AWS Credentials Used from GitHub Actions and Non-CI/CD Infrastructure High Elastic TOML
AWS EC2 Instance Console Login via Assumed Role High Elastic TOML
AWS EC2 Instance Profile Associated with Running Instance High Elastic TOML
AWS IAM API Calls via Temporary Session Tokens High Elastic TOML

+ 113 more from elastic/detection-rules → showing the 10 highest-severity

Azure/Azure-Sentinel

45 rules
Detection Severity Format
Addition of a Temporary Access Pass to a Privileged Account High KQL
Changes to PIM Settings High KQL
URL Added to Application from Unknown Domain High KQL
Application ID URI Changed Medium KQL
Application Redirect URL Update Medium KQL
Authentication Attempt from New Country Medium KQL
Authentications of Privileged Accounts Outside of Expected Controls Medium KQL
Changes to Application Ownership Medium KQL
Conditional Access Policy Modified by New User Medium KQL
End-user consent stopped due to risk-based consent Medium KQL

+ 35 more from Azure/Azure-Sentinel → showing the 10 highest-severity

SigmaHQ/sigma

41 rules
Detection Severity Format
Application AppID Uri Configuration Changes High Sigma
Application URI Configuration Changes High Sigma
AWS IAM S3Browser LoginProfile Creation High Sigma
AWS IAM S3Browser Templated S3 Bucket Policy Creation High Sigma
AWS IAM S3Browser User or AccessKey Creation High Sigma
Azure Subscription Permission Elevation Via ActivityLogs High Sigma
Changes To PIM Settings High Sigma
Okta New Admin Console Behaviours High Sigma
PIM Approvals And Deny Elevation High Sigma
Potential MFA Bypass Using Legacy Client Authentication High Sigma

+ 31 more from SigmaHQ/sigma → showing the 10 highest-severity

panther-labs/panther-analysis

27 rules
Detection Severity Format
Kubernetes System Role Modified or Deleted Critical Panther Python
Slack Primary Owner Transferred Critical Panther Python
AWS Compromised IAM Key Quarantine High Panther Python
AWS IMDS Credential Usage Outside Expected Services High Panther Python
Azure Protection Multiple Alerts for User High Panther Python
GAIA GCPW Credential Theft Attack Chain High Panther Python
Kubernetes Role With Node Proxy Permissions Created High Panther Python
Kubernetes Role With Pod Exec Permissions Created High Panther Python
Kubernetes Role With Wildcard Permissions Created High Panther Python
Kubernetes Service Account Token Theft from Pod High Panther Python

+ 17 more from panther-labs/panther-analysis → showing the 10 highest-severity

splunk/security_content

20 rules
Detection Severity Format
ASL AWS Create Policy Version to allow all resources Undefined SPL
AWS Create Policy Version to allow all resources Undefined SPL
AWS SetDefaultPolicyVersion Undefined SPL
AWS Successful Single-Factor Authentication Undefined SPL
Azure AD Authentication Failed During MFA Challenge Undefined SPL
Azure AD Multiple Failed MFA Requests For User Undefined SPL
Azure AD Service Principal Authentication Undefined SPL
Azure AD Successful PowerShell Authentication Undefined SPL
Azure AD Successful Single-Factor Authentication Undefined SPL
Azure Runbook Webhook Created Undefined SPL

+ 10 more from splunk/security_content → showing the 10 highest-severity

chronicle/detection-rules

16 rules
Detection Severity Format
aws_api_call_outside_of_organization High YARA-L
aws_iam_administrator_access_policy_attached High YARA-L
gcp_workload_identity_pool_disabled_or_deleted High YARA-L
o365_admin_login_activity_to_uncommon_mscloud_apps High YARA-L
onelogin_super_user_privileges_assigned High YARA-L
aws_user_creates_permanent_access_key Medium YARA-L
entra_id_admin_login_activity_to_uncommon_mscloud_apps Medium YARA-L
gcp_kms_decryption_by_unexpected_service_account Medium YARA-L
google_workspace_external_user_added_to_group Medium YARA-L
google_workspace_user_unsuspended Medium YARA-L

+ 6 more from chronicle/detection-rules → showing the 10 highest-severity

Wazuh Core Ruleset

6 rules
Detection Severity Format
Amazon Security Lake - CloudTrail - Failed API Operation "" with error "" from by user . · api.response.error = null Low Wazuh XML
Amazon Security Lake - CloudTrail - Successful API Operation "". · api.response.error = null, api.operation = \.* Low Wazuh XML
Amazon Security Lake - CloudTrail - Successful API Operation "" by user . · api.response.error = null, api.operation = \.* Low Wazuh XML
Amazon Security Lake - CloudTrail - Successful API Operation "" by user from ip. · api.response.error = null, api.operation = \.* Low Wazuh XML
Amazon Security Lake - CloudTrail - Successful API Operation "" from ip. · api.response.error = null, api.operation = \.* Low Wazuh XML
Amazon Security Lake - CloudTrail - Too many failed API Operations "" from ip. · rule 99021 Low Wazuh XML

Bert-JanP/Hunting-Queries-Detection-Rules

5 rules
Detection Severity Format
CA Application SignIn Failures Undefined KQL
CA User SignIn Failures Undefined KQL
Cloud Persistence Activities by User At Risk Undefined KQL
MITRE ATT&CK Mapping Undefined KQL
New Authentication App Detected Undefined KQL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.