Cross-source coverage
T1586 / ATT&CK
Compromise Accounts
44 rules across 6 sources.
From MITRE ATT&CK 19.2
Adversaries may compromise accounts with services that can be used during targeting. For operations incorporating social engineering, the utilization of an online persona may be important. Rather than creating and cultivating accounts (i.e. Establish Accounts), adversaries may compromise existing accounts. Utilizing an existing persona may engender a level of trust in a potential victim if they have a relationship, or knowledge of, the compromised persona.
A variety of methods exist for compromising accounts, such as gathering credentials via Phishing for Information, purchasing credentials from third-party sites, brute forcing credentials (ex: password reuse from breach credential dumps), or paying employees, suppliers or business partners for access to credentials. Prior to compromising accounts, adversaries may conduct Reconnaissance to inform decisions about which accounts to compromise to further their operation.
Personas may exist on a single site or across multiple sites (ex: Facebook, LinkedIn, Twitter, Google, etc.). Compromised accounts may require additional development, this could include filling out or modifying profile information, further developing social networks, or incorporating photos.
Adversaries may directly leverage compromised email accounts for Phishing for Information or Phishing.
- Tactics
- Resource Development
- Platforms
- PRE
- Telemetry
-
PersonaNetwork Traffic
How MITRE says to detect it DET0876
Detection of Compromise Accounts
PRE Analytic 2008
Consider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently modified accounts making numerous connection requests to accounts affiliated with your organization. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Phishing](https://attack.mitre.org/techniques/T1566)). Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
PersonaNoneNetwork TrafficNone
Sub-techniques with coverage
Counted in the 44 above — a rule tagged a sub-technique covers this technique too.
splunk/security_content
36 rules| Detection | Severity | Format |
|---|---|---|
| ASL AWS Credential Access GetPasswordData | Undefined | SPL |
| ASL AWS Credential Access RDS Password reset | Undefined | SPL |
| ASL AWS Multi-Factor Authentication Disabled | Undefined | SPL |
| AWS Console Login Failed During MFA Challenge | Undefined | SPL |
| AWS Credential Access Failed Login | Undefined | SPL |
| AWS Credential Access GetPasswordData | Undefined | SPL |
| AWS Credential Access RDS Password reset | Undefined | SPL |
| AWS Multi-Factor Authentication Disabled | Undefined | SPL |
| AWS Multiple Failed MFA Requests For User | Undefined | SPL |
| AWS Successful Console Authentication From Multiple IPs | Undefined | SPL |
+ 26 more from splunk/security_content → showing the 10 highest-severity
SigmaHQ/sigma
3 rules| Detection | Severity | Format |
|---|---|---|
| Bitbucket Unauthorized Access To A Resource | Critical | Sigma |
| Bitbucket Unauthorized Full Data Export Triggered | Critical | Sigma |
| Okta Suspicious Activity Reported by End-user | High | Sigma |
Azure/Azure-Sentinel
2 rules| Detection | Severity | Format |
|---|---|---|
| Storage Account Key Enumeration | Undefined | KQL |
| Storage Alert Correlation with CommonSecurityLogs and StorageLogs | Undefined | KQL |
Wazuh Core Ruleset
1 rule| Detection | Severity | Format |
|---|---|---|
| MS Graph message: A user's credentials were compromised or stolen. This is a true positive alert. | Critical | Wazuh XML |
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| aws_successful_console_authentication_from_multiple_ips | Medium | YARA-L |
panther-labs/panther-analysis
1 rule| Detection | Severity | Format |
|---|---|---|
| Azure Role Changed PIM | Medium | Panther Python |