Cross-source coverage

T1098 / ATT&CK

Account Manipulation

494 rules · 489 families across 11 sources.

2 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

In order to create or manipulate accounts, the adversary must already have sufficient permissions on systems or the domain. However, account manipulation may also lead to privilege escalation where modifications grant access to additional roles, permissions, or higher-privileged Valid Accounts.

Platforms
Containers · ESXi · IaaS · Identity Provider · Linux · macOS · Network Devices · Office Suite · SaaS · Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLauditd:PATHmacos:unifiedlogsaas:oktaesxi:vpxam365:unified

How MITRE says to detect it DET0096

Account Manipulation Behavior Chain Detection

Windows Analytic 0265

Account attribute changes (e.g., password set, group membership, servicePrincipalName, logon hours) correlated with unusual process lineage or timing, indicating privilege escalation or persistence via valid accounts.

  • WinEventLog:Security EventCode=4738, 4728, 4670
  • WinEventLog:Sysmon EventCode=1

Linux Analytic 0266

Use of native tools or scripting (e.g., `usermod`, `passwd`, `groupmod`) to escalate permissions or persist access on existing users, correlated with login or process events.

  • auditd:SYSCALL usermod, groupmod, passwd
  • auditd:PATH /etc/passwd or /etc/group file write

macOS Analytic 0267

Modifications to user accounts via `dscl`, `pwpolicy`, or System Preferences CLI (`sysadminctl`) that alter user groups, enable root, or bypass MDM restrictions.

  • macos:unifiedlog com.apple.accountsd, com.apple.opendirectoryd

Identity Provider Analytic 0268

Modifications to SSO/SAML user attributes (e.g., `isAdmin`, `role`, MFA bypass, App assignments) often through CLI, API, or rogue IdP apps.

  • saas:okta User Attribute Modified / Role Assignment Changed

ESXi Analytic 0269

Addition of new users or changes to role permissions (e.g., ReadOnly -> Admin) via API or vSphere Client, particularly from non-jumpbox IPs.

  • esxi:vpxa vim.SessionManager.login / vim.AccountManager.createUser

SaaS Analytic 0270

Role escalation (e.g., Editor → Owner) in cloud collaboration tools (Google Workspace, O365) or file sharing apps to maintain elevated access.

  • m365:unified Admin Activity > Role Change or Sharing Change

Sub-techniques with coverage

Counted in the 494 above — a rule tagged a sub-technique covers this technique too.


elastic/detection-rules

168 rules
Detection Severity Format
AdminSDHolder Backdoor High Elastic TOML
AdminSDHolder SDProp Exclusion Added High Elastic TOML
Application Added to Google Workspace Domain High Elastic TOML
AWS EC2 CreateKeyPair by New Principal from Non-Cloud AS Organization High Elastic TOML
AWS EC2 Instance Connect SSH Public Key Uploaded High Elastic TOML
AWS EKS Access Entry Granted Cluster Admin Policy High Elastic TOML
AWS First Occurrence of STS GetFederationToken Request by User High Elastic TOML
AWS IAM AdministratorAccess Policy Attached to User High Elastic TOML
AWS IAM API Calls via Temporary Session Tokens High Elastic TOML
AWS IAM Credentials Added to a Bedrock API Key Phantom User High Elastic TOML

+ 158 more from elastic/detection-rules → showing the 10 highest-severity

panther-labs/panther-analysis

81 rules
Detection Severity Format
AWS RDS Instance Modified to be Publicly Accessible Critical Panther Python
GitHub Org Authentication Method Changed Critical Panther Python
Kubernetes System Role Modified or Deleted Critical Panther Python
Root Account Access Key Created Critical Panther Python
Slack Primary Owner Transferred Critical Panther Python
An administrator account was created, deleted, or modified. High Panther Python
Anthropic Primary Owner Transferred High Panther Python
A User Role with Sensitive Permissions has been Created High Panther Python
A User's Panther Account was Modified High Panther Python
Auth0 New Admin Invited WITH Tenant Member Account Deletion High Panther Python

+ 71 more from panther-labs/panther-analysis → showing the 10 highest-severity

splunk/security_content

65 rules
Detection Severity Format
ASL AWS IAM Delete Policy Undefined SPL
ASL AWS IAM Failure Group Deletion Undefined SPL
ASL AWS IAM Successful Group Deletion Undefined SPL
AWS IAM Delete Policy Undefined SPL
AWS IAM Failure Group Deletion Undefined SPL
AWS IAM Successful Group Deletion Undefined SPL
Azure AD Admin Consent Bypassed by Service Principal Undefined SPL
Azure AD Application Administrator Role Assigned Undefined SPL
Azure AD FullAccessAsApp Permission Assigned Undefined SPL
Azure AD Global Administrator Role Assigned Undefined SPL

+ 55 more from splunk/security_content → showing the 10 highest-severity

Azure/Azure-Sentinel

49 rules
Detection Severity Format
DSRM Account Abuse High KQL
Anomalous login followed by Teams action Medium KQL
Detect PIM Alert Disabling activity Medium KQL
Group created then added to built in domain local or global group Medium KQL
High risk Office operation conducted by IP Address that recently attempted to log into a disabled account Medium KQL
NRT Malicious Inbox Rule Medium KQL
OAuth Application Required Resource Access Update Medium KQL
Sign-ins from IPs that attempt sign-ins to disabled accounts Medium KQL
Sign-ins from IPs that attempt sign-ins to disabled accounts (Uses Authentication Normalization) Medium KQL
User account created and deleted within 10 mins Medium KQL

+ 39 more from Azure/Azure-Sentinel → showing the 10 highest-severity

SigmaHQ/sigma

44 rules
Detection Severity Format
Active Directory User Backdoors High Sigma
Added Credentials to Existing Application High Sigma
Anomalous User Activity High Sigma
App Granted Privileged Delegated Or App Permissions High Sigma
AWS User Login Profile Was Modified High Sigma
Bulk Deletion Changes To Privileged Account Permissions High Sigma
Cisco Local Accounts High Sigma
Enabled User Right in AD to Control User Objects High Sigma
ESXi Admin Permission Assigned To Account Via ESXCLI High Sigma
Password Change on Directory Service Restore Mode (DSRM) Account High Sigma

+ 34 more from SigmaHQ/sigma → showing the 10 highest-severity

chronicle/detection-rules

29 rules
Detection Severity Format
sap_change_documents_sensitive_profile_assignment Critical YARA-L
sap_change_documents_sensitive_profile_assignment_data_table Critical YARA-L
sap_change_documents_sensitive_role_assignment Critical YARA-L
sap_critial_role_assigned_to_new_user Critical YARA-L
sap_critical_authorization_value_changed Critical YARA-L
sap_critical_role_assigned_to_new_user Critical YARA-L
aws_iam_activity_by_s3_browser_utility High YARA-L
aws_iam_activity_from_ec2_instance High YARA-L
entra_id_recently_created_user_assigned_entra_id_roles High YARA-L
gcp_iam_organization_policy_updated_or_deleted High YARA-L

+ 19 more from chronicle/detection-rules → showing the 10 highest-severity

Wazuh Core Ruleset

26 rules
Detection Severity Format
"Null" user changed some information. High Wazuh XML
Office 365: User got FullAccess permissions in Exchange · office365.Parameters = \"Value\":\s*\"FullAccess\" High Wazuh XML
Possible IAM Role backdooring: IAM role granted from an external account. High Wazuh XML
General account database changed Medium Wazuh XML
Information from the user was changed. Medium Wazuh XML
Office 365: Added user Medium Wazuh XML
User account changed Medium Wazuh XML
User account disabled or deleted Medium Wazuh XML
User account enabled or created Medium Wazuh XML
Windows: General account database changed. Medium Wazuh XML

+ 16 more from Wazuh Core Ruleset → showing the 10 highest-severity

socfortress/Wazuh-Rules

22 rules · 21 families
Detection Severity Format
Powerview Add-DomainObjectAcl DCSync AD Extend Right Critical Wazuh XML
operation. · office_365.Operation = MemberRemoved High Wazuh XML
Sysmon - Event 1: Process creation · Account Manipulation (T1098) 2 variants High Wazuh XML
Sysmon - Event 1: Process creation · Add Domain User to Group (T1098) High Wazuh XML
Sysmon - Event 1: Process creation · Create Domain Account (T1098) High Wazuh XML
Sysmon - Event 1: Process creation · Modify Local Account Description (T1098) High Wazuh XML
Sysmon - Event 1: Process creation · Password Policy Check - Set-ADAccountPassword (T1098) High Wazuh XML
Sysmon - Event 1: Process creation · Rename Administrator Account (T1098) High Wazuh XML
Sysmon - Event 1: Process creation · Sync DSRM Password (T1098) High Wazuh XML
Suspicious read access to SSH authorized_keys file (T1098.004) Medium Wazuh XML

+ 12 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

Bert-JanP/Hunting-Queries-Detection-Rules

6 rules
Detection Severity Format
Commandline Group Addition Undefined KQL
Detect when an account has been changed in order for the password to never expire Undefined KQL
List *.All MS Graph Permissions Added Undefined KQL
List MS Graph Mail Permissions Added Undefined KQL
MITRE ATT&CK Mapping Undefined KQL
Password change after succesful brute force Undefined KQL

falcosecurity/rules

3 rules
Detection Severity Format
Write below etc High Falco YAML
Adding ssh keys to authorized_keys Medium Falco YAML
User mgmt binaries Low Falco YAML

chainguard-dev/osquery-defense-kit

1 rule
Detection Severity Format
Find unexpected SSH authorized keys Undefined osquery SQL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.