Cross-source coverage
T1098 / ATT&CK
Account Manipulation
494 rules · 489 families across 11 sources.
2 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
In order to create or manipulate accounts, the adversary must already have sufficient permissions on systems or the domain. However, account manipulation may also lead to privilege escalation where modifications grant access to additional roles, permissions, or higher-privileged Valid Accounts.
- Tactics
- Persistence · Privilege Escalation
- Platforms
- Containers · ESXi · IaaS · Identity Provider · Linux · macOS · Network Devices · Office Suite · SaaS · Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLauditd:PATHmacos:unifiedlogsaas:oktaesxi:vpxam365:unified
How MITRE says to detect it DET0096
Account Manipulation Behavior Chain Detection
Windows Analytic 0265
Account attribute changes (e.g., password set, group membership, servicePrincipalName, logon hours) correlated with unusual process lineage or timing, indicating privilege escalation or persistence via valid accounts.
WinEventLog:SecurityEventCode=4738, 4728, 4670WinEventLog:SysmonEventCode=1
Linux Analytic 0266
Use of native tools or scripting (e.g., `usermod`, `passwd`, `groupmod`) to escalate permissions or persist access on existing users, correlated with login or process events.
auditd:SYSCALLusermod, groupmod, passwdauditd:PATH/etc/passwd or /etc/group file write
macOS Analytic 0267
Modifications to user accounts via `dscl`, `pwpolicy`, or System Preferences CLI (`sysadminctl`) that alter user groups, enable root, or bypass MDM restrictions.
macos:unifiedlogcom.apple.accountsd, com.apple.opendirectoryd
Identity Provider Analytic 0268
Modifications to SSO/SAML user attributes (e.g., `isAdmin`, `role`, MFA bypass, App assignments) often through CLI, API, or rogue IdP apps.
saas:oktaUser Attribute Modified / Role Assignment Changed
ESXi Analytic 0269
Addition of new users or changes to role permissions (e.g., ReadOnly -> Admin) via API or vSphere Client, particularly from non-jumpbox IPs.
esxi:vpxavim.SessionManager.login / vim.AccountManager.createUser
SaaS Analytic 0270
Role escalation (e.g., Editor → Owner) in cloud collaboration tools (Google Workspace, O365) or file sharing apps to maintain elevated access.
m365:unifiedAdmin Activity > Role Change or Sharing Change
Sub-techniques with coverage
Counted in the 494 above — a rule tagged a sub-technique covers this technique too.
elastic/detection-rules
168 rules| Detection | Severity | Format |
|---|---|---|
| AdminSDHolder Backdoor | High | Elastic TOML |
| AdminSDHolder SDProp Exclusion Added | High | Elastic TOML |
| Application Added to Google Workspace Domain | High | Elastic TOML |
| AWS EC2 CreateKeyPair by New Principal from Non-Cloud AS Organization | High | Elastic TOML |
| AWS EC2 Instance Connect SSH Public Key Uploaded | High | Elastic TOML |
| AWS EKS Access Entry Granted Cluster Admin Policy | High | Elastic TOML |
| AWS First Occurrence of STS GetFederationToken Request by User | High | Elastic TOML |
| AWS IAM AdministratorAccess Policy Attached to User | High | Elastic TOML |
| AWS IAM API Calls via Temporary Session Tokens | High | Elastic TOML |
| AWS IAM Credentials Added to a Bedrock API Key Phantom User | High | Elastic TOML |
+ 158 more from elastic/detection-rules → showing the 10 highest-severity
panther-labs/panther-analysis
81 rules| Detection | Severity | Format |
|---|---|---|
| AWS RDS Instance Modified to be Publicly Accessible | Critical | Panther Python |
| GitHub Org Authentication Method Changed | Critical | Panther Python |
| Kubernetes System Role Modified or Deleted | Critical | Panther Python |
| Root Account Access Key Created | Critical | Panther Python |
| Slack Primary Owner Transferred | Critical | Panther Python |
| An administrator account was created, deleted, or modified. | High | Panther Python |
| Anthropic Primary Owner Transferred | High | Panther Python |
| A User Role with Sensitive Permissions has been Created | High | Panther Python |
| A User's Panther Account was Modified | High | Panther Python |
| Auth0 New Admin Invited WITH Tenant Member Account Deletion | High | Panther Python |
+ 71 more from panther-labs/panther-analysis → showing the 10 highest-severity
splunk/security_content
65 rules| Detection | Severity | Format |
|---|---|---|
| ASL AWS IAM Delete Policy | Undefined | SPL |
| ASL AWS IAM Failure Group Deletion | Undefined | SPL |
| ASL AWS IAM Successful Group Deletion | Undefined | SPL |
| AWS IAM Delete Policy | Undefined | SPL |
| AWS IAM Failure Group Deletion | Undefined | SPL |
| AWS IAM Successful Group Deletion | Undefined | SPL |
| Azure AD Admin Consent Bypassed by Service Principal | Undefined | SPL |
| Azure AD Application Administrator Role Assigned | Undefined | SPL |
| Azure AD FullAccessAsApp Permission Assigned | Undefined | SPL |
| Azure AD Global Administrator Role Assigned | Undefined | SPL |
+ 55 more from splunk/security_content → showing the 10 highest-severity
Azure/Azure-Sentinel
49 rules| Detection | Severity | Format |
|---|---|---|
| DSRM Account Abuse | High | KQL |
| Anomalous login followed by Teams action | Medium | KQL |
| Detect PIM Alert Disabling activity | Medium | KQL |
| Group created then added to built in domain local or global group | Medium | KQL |
| High risk Office operation conducted by IP Address that recently attempted to log into a disabled account | Medium | KQL |
| NRT Malicious Inbox Rule | Medium | KQL |
| OAuth Application Required Resource Access Update | Medium | KQL |
| Sign-ins from IPs that attempt sign-ins to disabled accounts | Medium | KQL |
| Sign-ins from IPs that attempt sign-ins to disabled accounts (Uses Authentication Normalization) | Medium | KQL |
| User account created and deleted within 10 mins | Medium | KQL |
+ 39 more from Azure/Azure-Sentinel → showing the 10 highest-severity
SigmaHQ/sigma
44 rules| Detection | Severity | Format |
|---|---|---|
| Active Directory User Backdoors | High | Sigma |
| Added Credentials to Existing Application | High | Sigma |
| Anomalous User Activity | High | Sigma |
| App Granted Privileged Delegated Or App Permissions | High | Sigma |
| AWS User Login Profile Was Modified | High | Sigma |
| Bulk Deletion Changes To Privileged Account Permissions | High | Sigma |
| Cisco Local Accounts | High | Sigma |
| Enabled User Right in AD to Control User Objects | High | Sigma |
| ESXi Admin Permission Assigned To Account Via ESXCLI | High | Sigma |
| Password Change on Directory Service Restore Mode (DSRM) Account | High | Sigma |
+ 34 more from SigmaHQ/sigma → showing the 10 highest-severity
chronicle/detection-rules
29 rules| Detection | Severity | Format |
|---|---|---|
| sap_change_documents_sensitive_profile_assignment | Critical | YARA-L |
| sap_change_documents_sensitive_profile_assignment_data_table | Critical | YARA-L |
| sap_change_documents_sensitive_role_assignment | Critical | YARA-L |
| sap_critial_role_assigned_to_new_user | Critical | YARA-L |
| sap_critical_authorization_value_changed | Critical | YARA-L |
| sap_critical_role_assigned_to_new_user | Critical | YARA-L |
| aws_iam_activity_by_s3_browser_utility | High | YARA-L |
| aws_iam_activity_from_ec2_instance | High | YARA-L |
| entra_id_recently_created_user_assigned_entra_id_roles | High | YARA-L |
| gcp_iam_organization_policy_updated_or_deleted | High | YARA-L |
+ 19 more from chronicle/detection-rules → showing the 10 highest-severity
Wazuh Core Ruleset
26 rules| Detection | Severity | Format |
|---|---|---|
| "Null" user changed some information. | High | Wazuh XML |
| Office 365: User got FullAccess permissions in Exchange · office365.Parameters = \"Value\":\s*\"FullAccess\" | High | Wazuh XML |
| Possible IAM Role backdooring: IAM role granted from an external account. | High | Wazuh XML |
| General account database changed | Medium | Wazuh XML |
| Information from the user was changed. | Medium | Wazuh XML |
| Office 365: Added user | Medium | Wazuh XML |
| User account changed | Medium | Wazuh XML |
| User account disabled or deleted | Medium | Wazuh XML |
| User account enabled or created | Medium | Wazuh XML |
| Windows: General account database changed. | Medium | Wazuh XML |
+ 16 more from Wazuh Core Ruleset → showing the 10 highest-severity
socfortress/Wazuh-Rules
22 rules · 21 families| Detection | Severity | Format |
|---|---|---|
| Powerview Add-DomainObjectAcl DCSync AD Extend Right | Critical | Wazuh XML |
| operation. · office_365.Operation = MemberRemoved | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Account Manipulation (T1098) 2 variants | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Add Domain User to Group (T1098) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Create Domain Account (T1098) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Modify Local Account Description (T1098) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Password Policy Check - Set-ADAccountPassword (T1098) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Rename Administrator Account (T1098) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Sync DSRM Password (T1098) | High | Wazuh XML |
| Suspicious read access to SSH authorized_keys file (T1098.004) | Medium | Wazuh XML |
+ 12 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
Bert-JanP/Hunting-Queries-Detection-Rules
6 rules| Detection | Severity | Format |
|---|---|---|
| Commandline Group Addition | Undefined | KQL |
| Detect when an account has been changed in order for the password to never expire | Undefined | KQL |
| List *.All MS Graph Permissions Added | Undefined | KQL |
| List MS Graph Mail Permissions Added | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
| Password change after succesful brute force | Undefined | KQL |
falcosecurity/rules
3 rules| Detection | Severity | Format |
|---|---|---|
| Write below etc | High | Falco YAML |
| Adding ssh keys to authorized_keys | Medium | Falco YAML |
| User mgmt binaries | Low | Falco YAML |
chainguard-dev/osquery-defense-kit
1 rule| Detection | Severity | Format |
|---|---|---|
| Find unexpected SSH authorized keys | Undefined | osquery SQL |