Cross-source coverage

T1586 / ATT&CK

Compromise Accounts

44 rules across 6 sources.

From MITRE ATT&CK 19.2

Adversaries may compromise accounts with services that can be used during targeting. For operations incorporating social engineering, the utilization of an online persona may be important. Rather than creating and cultivating accounts (i.e. Establish Accounts), adversaries may compromise existing accounts. Utilizing an existing persona may engender a level of trust in a potential victim if they have a relationship, or knowledge of, the compromised persona.

A variety of methods exist for compromising accounts, such as gathering credentials via Phishing for Information, purchasing credentials from third-party sites, brute forcing credentials (ex: password reuse from breach credential dumps), or paying employees, suppliers or business partners for access to credentials. Prior to compromising accounts, adversaries may conduct Reconnaissance to inform decisions about which accounts to compromise to further their operation.

Personas may exist on a single site or across multiple sites (ex: Facebook, LinkedIn, Twitter, Google, etc.). Compromised accounts may require additional development, this could include filling out or modifying profile information, further developing social networks, or incorporating photos.

Adversaries may directly leverage compromised email accounts for Phishing for Information or Phishing.

Platforms
PRE
Telemetry
PersonaNetwork Traffic

How MITRE says to detect it DET0876

Detection of Compromise Accounts

PRE Analytic 2008

Consider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently modified accounts making numerous connection requests to accounts affiliated with your organization. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Phishing](https://attack.mitre.org/techniques/T1566)). Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).

  • Persona None
  • Network Traffic None

Sub-techniques with coverage

Counted in the 44 above — a rule tagged a sub-technique covers this technique too.


splunk/security_content

36 rules
Detection Severity Format
ASL AWS Credential Access GetPasswordData Undefined SPL
ASL AWS Credential Access RDS Password reset Undefined SPL
ASL AWS Multi-Factor Authentication Disabled Undefined SPL
AWS Console Login Failed During MFA Challenge Undefined SPL
AWS Credential Access Failed Login Undefined SPL
AWS Credential Access GetPasswordData Undefined SPL
AWS Credential Access RDS Password reset Undefined SPL
AWS Multi-Factor Authentication Disabled Undefined SPL
AWS Multiple Failed MFA Requests For User Undefined SPL
AWS Successful Console Authentication From Multiple IPs Undefined SPL

+ 26 more from splunk/security_content → showing the 10 highest-severity

SigmaHQ/sigma

3 rules
Detection Severity Format
Bitbucket Unauthorized Access To A Resource Critical Sigma
Bitbucket Unauthorized Full Data Export Triggered Critical Sigma
Okta Suspicious Activity Reported by End-user High Sigma

Azure/Azure-Sentinel

2 rules
Detection Severity Format
Storage Account Key Enumeration Undefined KQL
Storage Alert Correlation with CommonSecurityLogs and StorageLogs Undefined KQL

Wazuh Core Ruleset

1 rule
Detection Severity Format
MS Graph message: A user's credentials were compromised or stolen. This is a true positive alert. Critical Wazuh XML

chronicle/detection-rules

1 rule
Detection Severity Format
aws_successful_console_authentication_from_multiple_ips Medium YARA-L

panther-labs/panther-analysis

1 rule
Detection Severity Format
Azure Role Changed PIM Medium Panther Python

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.