{"id":"T1078","name":"Valid Accounts","url":"https://attack.mitre.org/techniques/T1078","tactics":["stealth","persistence","privilege-escalation","initial-access"],"platforms":["Containers","ESXi","IaaS","Identity Provider","Linux","macOS","Network Devices","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0560","stix_id":"x-mitre-detection-strategy--a6245075-b59f-46cf-8b76-e8d95c378a22","name":"Detection of Valid Account Abuse Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0560","analytics":[{"id":"AN1543","stix_id":"x-mitre-analytic--f9c3a686-2894-498d-9d04-7ac510752e1f","name":"Analytic 1543","description":"Detection of compromised or misused valid accounts via anomalous logon patterns, abnormal logon types, and inconsistent geographic or time-based activity across Windows endpoints.","url":"https://attack.mitre.org/detectionstrategies/DET0560#AN1543","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4624","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4776, 4625","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"LogonType","description":"Flag unexpected logon types (e.g., Type 10 for remote interactive logins) for sensitive accounts."},{"field":"TimeWindow","description":"Define acceptable hours for interactive logon activity (e.g., 9AM-6PM local)."},{"field":"GeoIPMismatch","description":"Trigger on location anomalies based on prior user behavior or policy."}],"live":true,"detection_strategies":["DET0560"],"techniques":["T1078"]},{"id":"AN1544","stix_id":"x-mitre-analytic--6cf46787-028d-4ac8-9dfa-58682edb3625","name":"Analytic 1544","description":"Detection of valid account misuse through SSH logins, sudo/su abuse, and service account anomalies outside expected patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0560#AN1544","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Connections","channel":"sshd or PAM logins","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"nsm-connections"}],"mutable_elements":[{"field":"UserContext","description":"Identify logins to root or sudoers not aligned with normal usage profiles."},{"field":"HostDensityThreshold","description":"Number of unique systems a user authenticates to in a time window."},{"field":"LoginMethod","description":"Trigger on rarely used access methods such as password instead of SSH key."}],"live":true,"detection_strategies":["DET0560"],"techniques":["T1078"]},{"id":"AN1545","stix_id":"x-mitre-analytic--d059a437-bf45-4b10-a36c-7e42e183d3c7","name":"Analytic 1545","description":"Detection of interactive and remote logins by service accounts or users at unusual times, with unexpected child process activity.","url":"https://attack.mitre.org/detectionstrategies/DET0560#AN1545","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"loginwindow, sshd","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"exec logs","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"LoginOrigin","description":"Login sourced from unexpected remote addresses."},{"field":"ProcessTreeDepth","description":"Track execution depth or anomalous chains post-login."}],"live":true,"detection_strategies":["DET0560"],"techniques":["T1078"]},{"id":"AN1546","stix_id":"x-mitre-analytic--aa255cdc-0b49-4ad3-951d-eab5582da56f","name":"Analytic 1546","description":"Detection of valid account abuse in IdP logs via geographic anomalies, impossible travel, risky sign-ins, and multiple MFA attempts or failures.","url":"https://attack.mitre.org/detectionstrategies/DET0560#AN1546","platforms":["Identity Provider"],"log_source_references":[{"name":"saas:okta","channel":"Sign-in logs / audit events","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"saas-okta"}],"mutable_elements":[{"field":"MFAFailureCount","description":"Threshold of failed MFA attempts before alerting."},{"field":"RiskScoreThreshold","description":"Custom threshold based on calculated identity risk."},{"field":"IPGeoVelocity","description":"Detect impossible travel (logins from two distant geolocations within short time)."}],"live":true,"detection_strategies":["DET0560"],"techniques":["T1078"]},{"id":"AN1547","stix_id":"x-mitre-analytic--dc062a09-572e-41fc-bfff-f654751a6a0f","name":"Analytic 1547","description":"Detection of containerized service accounts or compromised kubeconfigs being used for cluster access from unexpected nodes or IPs.","url":"https://attack.mitre.org/detectionstrategies/DET0560#AN1547","platforms":["Containers"],"log_source_references":[{"name":"kubernetes:audit","channel":"authentication.k8s.io","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"kubernetes-audit"}],"mutable_elements":[{"field":"ServiceAccountScope","description":"Validate access from expected namespaces only."},{"field":"ClusterIPWhitelist","description":"Permit kubeconfig usage from a limited set of IPs."}],"live":true,"detection_strategies":["DET0560"],"techniques":["T1078"]}],"live":true,"version":"1.0","techniques":["T1078"]}],"sigma_rules":[{"id":"128faeef-79dd-44ca-b43c-a9e236a60f49","title":"Unfamiliar Sign-In Properties","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-03","modified":null,"description":"Detects sign-in with properties that are unfamiliar to the user. The detection considers past sign-in history to look for anomalous sign-ins.","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#unfamiliar-sign-in-properties","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation","attack.initial-access"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_unfamilar_sign_in.yml","techniques":["T1078"],"cves":[]},{"id":"13f2d3f5-6497-44a7-bf5f-dc13ffafe5dc","title":"Azure Login Bypassing Conditional Access Policies","author":"Josh Nickels, Marius Rothenbücher","status":"experimental","level":"high","date":"2025-01-08","modified":null,"description":"Detects a successful login to the Microsoft Intune Company Portal which could allow bypassing Conditional Access Policies and InTune device trust using a tool like TokenSmith.\n","references":["https://labs.jumpsec.com/tokensmith-bypassing-intune-compliant-device-conditional-access/","https://github.com/JumpsecLabs/TokenSmith"],"logsource":{"product":"m365","service":"audit"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078"],"path":"rules/cloud/m365/audit/microsoft365_bypass_conditional_access.yml","techniques":["T1078"],"cves":[]},{"id":"1a41023f-1e70-4026-921a-4d9341a9038e","title":"Atypical Travel","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-03","modified":null,"description":"Identifies two sign-ins originating from geographically distant locations, where at least one of the locations may also be atypical for the user, given past behavior.","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#atypical-travel","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation","attack.initial-access"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_atypical_travel.yml","techniques":["T1078"],"cves":[]},{"id":"248649b7-d64f-46f0-9fb2-a52774166fb5","title":"Application Using Device Code Authentication Flow","author":"Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik'","status":"test","level":"medium","date":"2022-06-01","modified":null,"description":"Device code flow is an OAuth 2.0 protocol flow specifically for input constrained devices and is not used in all environments.\nIf this type of flow is seen in the environment and not being used in an input constrained device scenario, further investigation is warranted.\nThis can be a misconfigured application or potentially something malicious.\n","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#application-authentication-flows"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation","attack.initial-access"],"path":"rules/cloud/azure/signin_logs/azure_app_device_code_authentication.yml","techniques":["T1078"],"cves":[]},{"id":"259a9cdf-c4dd-4fa2-b243-2269e5ab18a2","title":"External Remote RDP Logon from Public IP","author":"Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity)","status":"test","level":"medium","date":"2023-01-19","modified":"2024-03-11","description":"Detects successful logon from public IP address via RDP. This can indicate a publicly-exposed RDP port.","references":["https://www.inversecos.com/2020/04/successful-4624-anonymous-logons-to.html","https://twitter.com/Purp1eW0lf/status/1616144561965002752"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1133","attack.t1078","attack.t1110"],"path":"rules/windows/builtin/security/account_management/win_security_successful_external_remote_rdp_login.yml","techniques":["T1133","T1078","T1110"],"cves":[]},{"id":"352a54e1-74ba-4929-9d47-8193d67aba1e","title":"Azure Domain Federation Settings Modified","author":"Austin Songer","status":"test","level":"medium","date":"2021-09-06","modified":"2022-06-08","description":"Identifies when an user or application modified the federation settings on the domain.","references":["https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-monitor-federation-changes"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078"],"path":"rules/cloud/azure/audit_logs/azure_federation_modified.yml","techniques":["T1078"],"cves":[]},{"id":"352a918a-34d8-4882-8470-44830c507aa3","title":"Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure","author":"jamesc-grafana","status":"test","level":"high","date":"2024-07-11","modified":null,"description":"Detects when an instance identity has taken an action that isn't inside SSM.\nThis can indicate that a compromised EC2 instance is being used as a pivot point.\n","references":["https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-identity-roles.html","https://ermetic.com/blog/aws/aws-ec2-imds-what-you-need-to-know/","https://www.packetmischief.ca/2023/07/31/amazon-ec2-credential-exfiltration-how-it-happens-and-how-to-mitigate-it/#lifting-credentials-from-imds-this-is-why-we-cant-have-nice-things"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.privilege-escalation","attack.initial-access","attack.persistence","attack.stealth","attack.t1078","attack.t1078.002"],"path":"rules/cloud/aws/cloudtrail/aws_cloudtrail_imds_malicious_usage.yml","techniques":["T1078","T1078.002"],"cves":[]},{"id":"39698b3f-da92-4bc6-bfb5-645a98386e45","title":"Win Susp Computer Name Containing Samtheadmin","author":"elhoim","status":"test","level":"critical","date":"2022-09-09","modified":"2023-01-04","description":"Detects suspicious computer name samtheadmin-{1..100}$ generated by hacktool","references":["https://twitter.com/malmoeb/status/1511760068743766026","https://github.com/helloexp/0day/blob/614227a7b9beb0e91e7e2c6a5e532e6f7a8e883c/00-CVE_EXP/CVE-2021-42287/sam-the-admin/sam_the_admin.py"],"logsource":{"product":"windows","service":"security"},"tags":["attack.initial-access","cve.2021-42278","cve.2021-42287","attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1078"],"path":"rules/windows/builtin/security/win_security_susp_computer_name.yml","techniques":["T1078"],"cves":["CVE-2021-42278","CVE-2021-42287"]},{"id":"3ff152b2-1388-4984-9cd9-a323323fdadf","title":"Interactive Logon to Server Systems","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2017-03-17","modified":"2023-12-15","description":"Detects interactive console logons to Server Systems","references":["Internal Research"],"logsource":{"product":"windows","service":"security"},"tags":["attack.lateral-movement","attack.initial-access","attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1078"],"path":"rules-placeholder/windows/builtin/security/win_security_susp_interactive_logons.yml","techniques":["T1078"],"cves":[]},{"id":"4ad97bf5-a514-41a4-abd3-4f3455ad4865","title":"Guest Users Invited To Tenant By Non Approved Inviters","author":"MikeDuddington, '@dudders1'","status":"test","level":"medium","date":"2022-07-28","modified":"2026-05-09","description":"Detects guest users being invited to tenant by non-approved inviters","references":["https://learn.microsoft.com/en-gb/entra/architecture/security-operations-user-accounts#monitoring-external-user-sign-ins","https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities#invited-users"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078"],"path":"rules-placeholder/cloud/azure/audit_logs/azure_ad_guest_users_invited_to_tenant_by_non_approved_inviters.yml","techniques":["T1078"],"cves":[]},{"id":"50e606bf-04ce-4ca7-9d54-3449494bbd4b","title":"Cisco LDP Authentication Failures","author":"Tim Brown","status":"test","level":"low","date":"2023-01-09","modified":null,"description":"Detects LDP failures which may be indicative of brute force attacks to manipulate MPLS labels","references":["https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf"],"logsource":{"product":"cisco","service":"ldp"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.collection","attack.stealth","attack.t1078","attack.t1110","attack.t1557"],"path":"rules/network/cisco/ldp/cisco_ldp_md5_auth_failed.yml","techniques":["T1078","T1110","T1557"],"cves":[]},{"id":"512cff7a-683a-43ad-afe0-dd398e872f36","title":"OpenCanary - Telnet Login Attempt","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where a Telnet service on an OpenCanary node has had a login attempt.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.command-and-control","attack.stealth","attack.t1133","attack.t1078"],"path":"rules/application/opencanary/opencanary_telnet_login_attempt.yml","techniques":["T1133","T1078"],"cves":[]},{"id":"55695bc0-c8cf-461f-a379-2535f563c854","title":"Applications That Are Using ROPC Authentication Flow","author":"Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik'","status":"test","level":"medium","date":"2022-06-01","modified":null,"description":"Resource owner password credentials (ROPC) should be avoided if at all possible as this requires the user to expose their current password credentials to the application directly.\nThe application then uses those credentials to authenticate the user against the identity provider.\n","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#application-authentication-flows"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation","attack.initial-access"],"path":"rules/cloud/azure/signin_logs/azure_app_ropc_authentication.yml","techniques":["T1078"],"cves":[]},{"id":"56fa3cd6-f8d6-4520-a8c7-607292971886","title":"Cisco BGP Authentication Failures","author":"Tim Brown","status":"test","level":"low","date":"2023-01-09","modified":"2023-01-23","description":"Detects BGP failures which may be indicative of brute force attacks to manipulate routing","references":["https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf"],"logsource":{"product":"cisco","service":"bgp"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.collection","attack.stealth","attack.t1078","attack.t1110","attack.t1557"],"path":"rules/network/cisco/bgp/cisco_bgp_md5_auth_failed.yml","techniques":["T1078","T1110","T1557"],"cves":[]},{"id":"572b12d4-9062-11ed-a1eb-0242ac120002","title":"Suspicious SignIns From A Non Registered Device","author":"Harjot Singh, '@cyb3rjy0t'","status":"test","level":"high","date":"2023-01-10","modified":"2025-07-02","description":"Detects risky authentication from a non AD registered device without MFA being required.","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-devices#non-compliant-device-sign-in"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078"],"path":"rules/cloud/azure/signin_logs/azure_ad_risky_sign_ins_with_singlefactorauth_from_unknown_devices.yml","techniques":["T1078"],"cves":[]},{"id":"58af08eb-f9e1-43c8-9805-3ad9b0482bd8","title":"Invalid PIM License","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-14","modified":null,"description":"Identifies when an organization doesn't have the proper license for PIM and is out of compliance.","references":["https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-configure-security-alerts#the-organization-doesnt-have-microsoft-entra-premium-p2-or-microsoft-entra-id-governance"],"logsource":{"product":"azure","service":"pim"},"tags":["attack.initial-access","attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation"],"path":"rules/cloud/azure/privileged_identity_management/azure_pim_invalid_license.yml","techniques":["T1078"],"cves":[]},{"id":"645fd80d-6c07-435b-9e06-7bc1b5656cba","title":"Roles Activated Too Frequently","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-14","modified":null,"description":"Identifies when the same privilege role has multiple activations by the same user.","references":["https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-configure-security-alerts#roles-are-being-activated-too-frequently"],"logsource":{"product":"azure","service":"pim"},"tags":["attack.initial-access","attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation"],"path":"rules/cloud/azure/privileged_identity_management/azure_pim_role_frequent_activation.yml","techniques":["T1078"],"cves":[]},{"id":"6ad91e31-53df-4826-bd27-0166171c8040","title":"Google Cloud Kubernetes Admission Controller","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-11-25","modified":"2022-12-18","description":"Identifies when an admission controller is executed in GCP Kubernetes.\nA Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server.\nThe behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster.\nAn adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster.\nFor example, attackers can intercept and modify the pod creation operations in the cluster and add their malicious container to every created pod. An adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials.\nAn adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.\n","references":["https://cloud.google.com/kubernetes-engine/docs"],"logsource":{"product":"gcp","service":"gcp.audit"},"tags":["attack.privilege-escalation","attack.initial-access","attack.persistence","attack.stealth","attack.t1078","attack.credential-access","attack.t1552","attack.t1552.007"],"path":"rules/cloud/gcp/audit/gcp_kubernetes_admission_controller.yml","techniques":["T1078","T1552","T1552.007"],"cves":[]},{"id":"6f583da0-3a90-4566-a4ed-83c09fe18bbf","title":"Account Created And Deleted Within A Close Time Frame","author":"Mark Morowczynski '@markmorow', MikeDuddington, '@dudders1', Tim Shelton","status":"test","level":"high","date":"2022-08-11","modified":"2022-08-18","description":"Detects when an account was created and deleted in a short period of time.","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#short-lived-accounts"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078"],"path":"rules/cloud/azure/audit_logs/azure_ad_account_created_deleted.yml","techniques":["T1078"],"cves":[]},{"id":"78d5cab4-557e-454f-9fb9-a222bd0d5edc","title":"External Remote SMB Logon from Public IP","author":"Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity)","status":"test","level":"high","date":"2023-01-19","modified":"2024-03-11","description":"Detects successful logon from public IP address via SMB. This can indicate a publicly-exposed SMB port.","references":["https://www.inversecos.com/2020/04/successful-4624-anonymous-logons-to.html","https://twitter.com/Purp1eW0lf/status/1616144561965002752"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1133","attack.t1078","attack.t1110"],"path":"rules/windows/builtin/security/account_management/win_security_successful_external_remote_smb_login.yml","techniques":["T1133","T1078","T1110"],"cves":[]},{"id":"7bbc309f-e2b1-4eb1-8369-131a367d67d3","title":"Too Many Global Admins","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-14","modified":null,"description":"Identifies an event where there are there are too many accounts assigned the Global Administrator role.","references":["https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-configure-security-alerts#there-are-too-many-global-administrators"],"logsource":{"product":"azure","service":"pim"},"tags":["attack.initial-access","attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation"],"path":"rules/cloud/azure/privileged_identity_management/azure_pim_too_many_global_admins.yml","techniques":["T1078"],"cves":[]},{"id":"821bcf4d-46c7-4b87-bc57-9509d3ba7c11","title":"Root Account Enable Via Dsenableroot","author":"Sohan G (D4rkCiph3r)","status":"test","level":"medium","date":"2023-08-22","modified":null,"description":"Detects attempts to enable the root account via \"dsenableroot\"","references":["https://github.com/redcanaryco/atomic-red-team/blob/b27a3cb25025161d49ac861cb216db68c46a3537/atomics/T1078.003/T1078.003.md","https://github.com/elastic/detection-rules/blob/4312d8c9583be524578a14fe6295c3370b9a9307/rules/macos/persistence_enable_root_account.toml","https://ss64.com/osx/dsenableroot.html"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.privilege-escalation","attack.stealth","attack.t1078","attack.t1078.001","attack.t1078.003","attack.initial-access","attack.persistence"],"path":"rules/macos/process_creation/proc_creation_macos_dsenableroot_enable_root_account.yml","techniques":["T1078","T1078.001","T1078.003"],"cves":[]},{"id":"8366030e-7216-476b-9927-271d79f13cf3","title":"Azure Unusual Authentication Interruption","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-11-26","modified":"2022-12-18","description":"Detects when there is a interruption in the authentication process.","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-accounts"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078"],"path":"rules/cloud/azure/signin_logs/azure_unusual_authentication_interruption.yml","techniques":["T1078"],"cves":[]},{"id":"8c6ec464-4ae4-43ac-936a-291da66ed13d","title":"Roles Are Not Being Used","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-14","modified":null,"description":"Identifies when a user has been assigned a privilege role and are not using that role.","references":["https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-configure-security-alerts#administrators-arent-using-their-privileged-roles"],"logsource":{"product":"azure","service":"pim"},"tags":["attack.initial-access","attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation"],"path":"rules/cloud/azure/privileged_identity_management/azure_pim_role_not_used.yml","techniques":["T1078"],"cves":[]},{"id":"92f84194-8d9a-4ee0-8699-c30bfac59780","title":"AWS Key Pair Import Activity","author":"Ivan Saakov","status":"experimental","level":"medium","date":"2024-12-19","modified":null,"description":"Detects the import of SSH key pairs into AWS EC2, which may indicate an attacker attempting to gain unauthorized access to instances. This activity could lead to initial access, persistence, or privilege escalation, potentially compromising sensitive data and operations.\n","references":["https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportKeyPair.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.initial-access","attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation"],"path":"rules/cloud/aws/cloudtrail/aws_ec2_import_key_pair_activity.yml","techniques":["T1078"],"cves":[]},{"id":"941e5c45-cda7-4864-8cea-bbb7458d194a","title":"Suspicious Remote Logon with Explicit Credentials","author":"oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Tim Shelton","status":"test","level":"medium","date":"2020-10-05","modified":"2022-08-03","description":"Detects suspicious processes logging on with explicit credentials","references":["https://drive.google.com/file/d/1lKya3_mLnR3UQuCoiYruO3qgu052_iS_/view"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078","attack.lateral-movement"],"path":"rules/windows/builtin/security/win_security_susp_logon_explicit_credentials.yml","techniques":["T1078"],"cves":[]},{"id":"944f6adb-7a99-4c69-80c1-b712579e93e6","title":"Suspicious Browser Activity","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-03","modified":null,"description":"Indicates anomalous behavior based on suspicious sign-in activity across multiple tenants from different countries in the same browser","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#suspicious-browser","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation","attack.initial-access"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_suspicious_browser.yml","techniques":["T1078"],"cves":[]},{"id":"94a66f46-5b64-46ce-80b2-75dcbe627cc0","title":"Roles Activation Doesn't Require MFA","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-14","modified":null,"description":"Identifies when a privilege role can be activated without performing mfa.","references":["https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-configure-security-alerts#roles-dont-require-multi-factor-authentication-for-activation"],"logsource":{"product":"azure","service":"pim"},"tags":["attack.initial-access","attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation"],"path":"rules/cloud/azure/privileged_identity_management/azure_pim_role_no_mfa_required.yml","techniques":["T1078"],"cves":[]},{"id":"9eb99343-d336-4020-a3cd-67f3819e68ee","title":"Account Tampering - Suspicious Failed Logon Reasons","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2017-02-19","modified":"2025-10-17","description":"This method uses uncommon error codes on failed logons to determine suspicious activity and tampering with accounts that have been disabled or somehow restricted.","references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4625","https://twitter.com/SBousseaden/status/1101431884540710913"],"logsource":{"product":"windows","service":"security"},"tags":["attack.persistence","attack.privilege-escalation","attack.initial-access","attack.stealth","attack.t1078"],"path":"rules/windows/builtin/security/win_security_susp_failed_logon_reasons.yml","techniques":["T1078"],"cves":[]},{"id":"a2cb56ff-4f46-437a-a0fa-ffa4d1303cba","title":"Azure AD Threat Intelligence","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-07","modified":null,"description":"Indicates user activity that is unusual for the user or consistent with known attack patterns.","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#azure-ad-threat-intelligence-sign-in","https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#azure-ad-threat-intelligence-user","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation","attack.initial-access"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_threat_intel.yml","techniques":["T1078"],"cves":[]},{"id":"a557ffe6-ac54-43d2-ae69-158027082350","title":"Huawei BGP Authentication Failures","author":"Tim Brown","status":"test","level":"low","date":"2023-01-09","modified":"2023-01-23","description":"Detects BGP failures which may be indicative of brute force attacks to manipulate routing.","references":["https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf"],"logsource":{"product":"huawei","service":"bgp"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.collection","attack.stealth","attack.t1078","attack.t1110","attack.t1557"],"path":"rules/network/huawei/bgp/huawei_bgp_auth_failed.yml","techniques":["T1078","T1110","T1557"],"cves":[]},{"id":"a61a3c56-4ce2-4351-a079-88ae4cbd2b58","title":"Azure Kubernetes Admission Controller","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-11-25","modified":"2022-12-18","description":"Identifies when an admission controller is executed in Azure Kubernetes.\nA Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server.\nThe behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster.\nAn adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster.\nFor example, attackers can intercept and modify the pod creation operations in the cluster and add their malicious container to every created pod.\nAn adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials.\nAn adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.\n","references":["https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes"],"logsource":{"product":"azure","service":"activitylogs"},"tags":["attack.privilege-escalation","attack.initial-access","attack.persistence","attack.stealth","attack.t1078","attack.credential-access","attack.t1552","attack.t1552.007"],"path":"rules/cloud/azure/activity_logs/azure_kubernetes_admission_controller.yml","techniques":["T1078","T1552","T1552.007"],"cves":[]},{"id":"a7c0ae48-8df8-42bf-91bd-2ea57e2f9d43","title":"Juniper BGP Missing MD5","author":"Tim Brown","status":"test","level":"low","date":"2023-01-09","modified":"2023-01-23","description":"Detects juniper BGP missing MD5 digest. Which may be indicative of brute force attacks to manipulate routing.","references":["https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf"],"logsource":{"product":"juniper","service":"bgp"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.collection","attack.stealth","attack.t1078","attack.t1110","attack.t1557"],"path":"rules/network/juniper/bgp/juniper_bgp_missing_md5.yml","techniques":["T1078","T1110","T1557"],"cves":[]},{"id":"adf9f4d2-559e-4f5c-95be-c28dff0b1476","title":"New Country","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-03","modified":null,"description":"Detects sign-ins from new countries. The detection considers past activity locations to determine new and infrequent locations.","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#new-country","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation","attack.initial-access"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_new_coutry_region.yml","techniques":["T1078"],"cves":[]},{"id":"aeaef14c-e5bf-4690-a9c8-835caad458bd","title":"PIM Alert Setting Changes To Disabled","author":"Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H'","status":"test","level":"high","date":"2022-08-09","modified":null,"description":"Detects when PIM alerts are set to disabled.","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-identity-management#azure-ad-roles-assignment"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1078"],"path":"rules/cloud/azure/audit_logs/azure_pim_alerts_disabled.yml","techniques":["T1078"],"cves":[]},{"id":"b1bc08d1-8224-4758-a0e6-fbcfc98c73bb","title":"Roles Assigned Outside PIM","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-14","modified":null,"description":"Identifies when a privilege role assignment has taken place outside of PIM and may indicate an attack.","references":["https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-configure-security-alerts#roles-are-being-assigned-outside-of-privileged-identity-management"],"logsource":{"product":"azure","service":"pim"},"tags":["attack.initial-access","attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation"],"path":"rules/cloud/azure/privileged_identity_management/azure_pim_role_assigned_outside_of_pim.yml","techniques":["T1078"],"cves":[]},{"id":"b2572bf9-e20a-4594-b528-40bde666525a","title":"Impossible Travel","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-03","modified":null,"description":"Identifies user activities originating from geographically distant locations within a time period shorter than the time it takes to travel from the first location to the second.","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#impossible-travel","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation","attack.initial-access"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_impossible_travel.yml","techniques":["T1078"],"cves":[]},{"id":"be4d9c86-d702-4030-b52e-c7859110e5e8","title":"Activity From Anonymous IP Address","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-03","modified":null,"description":"Identifies that users were active from an IP address that has been identified as an anonymous proxy IP address.","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#activity-from-anonymous-ip-address","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation","attack.initial-access"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_anonymous_ip_activity.yml","techniques":["T1078"],"cves":[]},{"id":"c191e2fa-f9d6-4ccf-82af-4f2aba08359f","title":"Logon from a Risky IP Address","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-08-23","modified":"2022-10-09","description":"Detects when a Microsoft Cloud App Security reported when a user signs into your sanctioned apps from a risky IP address.","references":["https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy","https://learn.microsoft.com/en-us/defender-cloud-apps/policy-template-reference"],"logsource":{"product":"m365","service":"threat_management"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078"],"path":"rules/cloud/m365/threat_management/microsoft365_logon_from_risky_ip_address.yml","techniques":["T1078"],"cves":[]},{"id":"c265cf08-3f99-46c1-8d59-328247057d57","title":"User Added to Local Administrator Group","author":"Florian Roth (Nextron Systems)","status":"stable","level":"medium","date":"2017-03-14","modified":"2021-01-17","description":"Detects the addition of a new member to the local administrator group, which could be legitimate activity or a sign of privilege escalation activity","references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4732","https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-identifiers"],"logsource":{"product":"windows","service":"security"},"tags":["attack.initial-access","attack.privilege-escalation","attack.stealth","attack.t1078","attack.persistence","attack.t1098"],"path":"rules/windows/builtin/security/win_security_user_added_to_local_administrators.yml","techniques":["T1078","T1098"],"cves":[]},{"id":"c98184ba-4a27-4e10-b7b7-da48e71f4d25","title":"Account Created And Deleted By Non Approved Users","author":"Mark Morowczynski '@markmorow', MikeDuddington, '@dudders1'","status":"test","level":"medium","date":"2022-08-11","modified":"2023-12-15","description":"Detects accounts that are created or deleted by non-approved users.","references":["https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/security-operations-user-accounts#short-lived-accounts"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1078"],"path":"rules-placeholder/cloud/azure/audit_logs/azure_ad_account_created_deleted_nonapproved_user.yml","techniques":["T1078"],"cves":[]},{"id":"ca9bf243-465e-494a-9e54-bf9fc239057d","title":"Azure Subscription Permission Elevation Via AuditLogs","author":"Austin Songer @austinsonger","status":"test","level":"high","date":"2021-11-26","modified":"2022-12-25","description":"Detects when a user has been elevated to manage all Azure Subscriptions.\nThis change should be investigated immediately if it isn't planned.\nThis setting could allow an attacker access to Azure subscriptions in your environment.\n","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-accounts#assignment-and-elevation"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078"],"path":"rules/cloud/azure/audit_logs/azure_subscription_permissions_elevation_via_auditlogs.yml","techniques":["T1078"],"cves":[]},{"id":"cd55f721-5623-4663-bd9b-5229cab5237d","title":"OpenCanary - SSH New Connection Attempt","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where an SSH service on an OpenCanary node has had a connection attempt.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.privilege-escalation","attack.initial-access","attack.lateral-movement","attack.persistence","attack.stealth","attack.t1133","attack.t1021","attack.t1078"],"path":"rules/application/opencanary/opencanary_ssh_new_connection.yml","techniques":["T1133","T1021","T1078"],"cves":[]},{"id":"cf1e5687-84e1-41af-97a9-158094efef53","title":"Privilege Role Sign-In Outside Expected Controls","author":"Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H'","status":"test","level":"high","date":"2022-08-11","modified":"2023-12-15","description":"Detects failed sign-in due to user not meeting expected controls for adminitrators","references":["https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/security-operations-privileged-accounts#things-to-monitor"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1078"],"path":"rules-placeholder/cloud/azure/signin_logs/azure_privileged_account_sigin_expected_controls.yml","techniques":["T1078"],"cves":[]},{"id":"d4498716-1d52-438f-8084-4a603157d131","title":"Password Provided In Command Line Of Net.EXE","author":"Tim Shelton (HAWK.IO)","status":"test","level":"medium","date":"2021-12-09","modified":"2023-02-21","description":"Detects a when net.exe is called with a password in the command line","references":["Internal Research"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.lateral-movement","attack.stealth","attack.t1021.002","attack.t1078"],"path":"rules/windows/process_creation/proc_creation_win_net_use_password_plaintext.yml","techniques":["T1021.002","T1078"],"cves":[]},{"id":"d7329412-13bd-44ba-a072-3387f804a106","title":"Guest Account Enabled Via Sysadminctl","author":"Sohan G (D4rkCiph3r)","status":"test","level":"low","date":"2023-02-18","modified":null,"description":"Detects attempts to enable the guest account using the sysadminctl utility","references":["https://ss64.com/osx/sysadminctl.html"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078","attack.t1078.001"],"path":"rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml","techniques":["T1078","T1078.001"],"cves":[]},{"id":"d7eab125-5f94-43df-8710-795b80fa1189","title":"Microsoft 365 - Impossible Travel Activity","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2020-07-06","modified":"2021-11-27","description":"Detects when a Microsoft Cloud App Security reported a risky sign-in attempt due to a login associated with an impossible travel.","references":["https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy","https://learn.microsoft.com/en-us/defender-cloud-apps/policy-template-reference"],"logsource":{"product":"m365","service":"threat_management"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078"],"path":"rules/cloud/m365/threat_management/microsoft365_impossible_travel_activity.yml","techniques":["T1078"],"cves":[]},{"id":"e3818659-5016-4811-a73c-dde4679169d2","title":"Suspicious Computer Machine Password by PowerShell","author":"frack113","status":"test","level":"medium","date":"2022-02-21","modified":null,"description":"The Reset-ComputerMachinePassword cmdlet changes the computer account password that the computers use to authenticate to the domain controllers in the domain.\nYou can use it to reset the password of the local computer.\n","references":["https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/reset-computermachinepassword?view=powershell-5.1","https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/"],"logsource":{"product":"windows","category":"ps_module"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078"],"path":"rules/windows/powershell/powershell_module/posh_pm_susp_reset_computermachinepassword.yml","techniques":["T1078"],"cves":[]},{"id":"e402c26a-267a-45bd-9615-bd9ceda6da85","title":"Stale Accounts In A Privileged Role","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-14","modified":null,"description":"Identifies when an account hasn't signed in during the past n number of days.","references":["https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-configure-security-alerts#potential-stale-accounts-in-a-privileged-role"],"logsource":{"product":"azure","service":"pim"},"tags":["attack.initial-access","attack.stealth","attack.t1078","attack.persistence","attack.privilege-escalation"],"path":"rules/cloud/azure/privileged_identity_management/azure_pim_account_stale.yml","techniques":["T1078"],"cves":[]},{"id":"eafe6f2b-cfec-4612-aec2-49563c33a087","title":"Google Workspace Government Attack Warning","author":"Tom Kluter","status":"experimental","level":"medium","date":"2026-04-28","modified":null,"description":"Detects a login attempt in Google Workspace flagged as a potential attack by a government-backed threat actor","references":["https://cloud.google.com/logging/docs/audit/gsuite-audit-logging","https://cloud.google.com/logging/docs/audit/understanding-audit-logs","https://developers.google.com/workspace/admin/reports/v1/appendix/activity/login#gov_attack_warning"],"logsource":{"product":"gcp","service":"google_workspace.login"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.impact","attack.stealth","attack.t1078"],"path":"rules/cloud/gcp/gworkspace/login/gcp_gworkspace_govattack.yml","techniques":["T1078"],"cves":[]},{"id":"ebbeb024-5b1d-4e16-9c0c-917f86c708a7","title":"User Added to an Administrator's Azure AD Role","author":"Raphaël CALVET, @MetallicHack","status":"test","level":"medium","date":"2021-10-04","modified":"2026-04-30","description":"User Added to an Administrator's Azure AD Role","references":["https://web.archive.org/web/20250904191633/https://m365internals.com/2021/07/13/what-ive-learned-from-doing-a-year-of-cloud-forensics-in-azure-ad/","https://research.splunk.com/cloud/a28f0bc3-3400-4a6e-a2da-89b9e95f0d2a/","https://analyticsrules.exchange/analyticrules/2a09f8cb-deb7-4c40-b08b-9137667f1c0b/","https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities#core-directory"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1098.003","attack.t1078"],"path":"rules/cloud/azure/audit_logs/azure_ad_user_added_to_admin_role.yml","techniques":["T1098.003","T1078"],"cves":[]},{"id":"eed82177-38f5-4299-8a76-098d50d225ab","title":"Kubernetes Admission Controller Modification","author":"kelnage","status":"test","level":"medium","date":"2024-07-11","modified":null,"description":"Detects when a modification (create, update or replace) action is taken that affects mutating or validating webhook configurations, as they can be used by an adversary to achieve persistence or exfiltrate access credentials.\n","references":["https://kubernetes.io/docs/reference/config-api/apiserver-audit.v1/","https://security.padok.fr/en/blog/kubernetes-webhook-attackers"],"logsource":{"product":"kubernetes","service":"audit"},"tags":["attack.privilege-escalation","attack.initial-access","attack.persistence","attack.stealth","attack.t1078","attack.credential-access","attack.t1552","attack.t1552.007"],"path":"rules/application/kubernetes/audit/kubernetes_audit_change_admission_controller.yml","techniques":["T1078","T1552","T1552.007"],"cves":[]},{"id":"f272fb46-25f2-422c-b667-45837994980f","title":"Authentications To Important Apps Using Single Factor Authentication","author":"MikeDuddington, '@dudders1'","status":"test","level":"medium","date":"2022-07-28","modified":"2026-05-08","description":"Detect when authentications to important application(s) only required single-factor authentication","references":["https://learn.microsoft.com/en-gb/entra/architecture/security-operations-user-accounts"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078"],"path":"rules-placeholder/cloud/azure/signin_logs/azure_ad_auth_to_important_apps_using_single_factor_auth.yml","techniques":["T1078"],"cves":[]},{"id":"f43f5d2f-3f2a-4cc8-b1af-81fde7dbaf0e","title":"AWS Suspicious SAML Activity","author":"Austin Songer","status":"test","level":"medium","date":"2021-09-22","modified":"2022-12-18","description":"Identifies when suspicious SAML activity has occurred in AWS. An adversary could gain backdoor access via SAML.","references":["https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateSAMLProvider.html","https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRoleWithSAML.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.initial-access","attack.lateral-movement","attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1078","attack.t1548","attack.t1550","attack.t1550.001"],"path":"rules/cloud/aws/cloudtrail/aws_susp_saml_activity.yml","techniques":["T1078","T1548","T1550","T1550.001"],"cves":[]},{"id":"f88e112a-21aa-44bd-9b01-6ee2a2bbbed1","title":"Failed Logon From Public IP","author":"NVISO","status":"test","level":"medium","date":"2020-05-06","modified":"2024-03-11","description":"Detects a failed logon attempt from a public IP. A login from a public IP can indicate a misconfigured firewall or network boundary.","references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4625"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.initial-access","attack.persistence","attack.stealth","attack.t1078","attack.t1190","attack.t1133"],"path":"rules/windows/builtin/security/account_management/win_security_susp_failed_logon_source.yml","techniques":["T1078","T1190","T1133"],"cves":[]},{"id":"ff7139bc-fdb1-4437-92f2-6afefe8884cb","title":"OpenCanary - SSH Login Attempt","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where an SSH service on an OpenCanary node has had a login attempt.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.privilege-escalation","attack.initial-access","attack.lateral-movement","attack.persistence","attack.stealth","attack.t1133","attack.t1021","attack.t1078"],"path":"rules/application/opencanary/opencanary_ssh_login_attempt.yml","techniques":["T1133","T1021","T1078"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-24016","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-39780","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-20035","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-31161","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-57968","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-20118","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-55591","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2024-37085","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-22948","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-20399","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-20359","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-21893","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-46805","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-27524","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-20273","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-20109","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-22515","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-28229","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-41179","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-20269","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-20867","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-28252","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-23397","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-22952","state":"stale","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-21674","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-26500","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-41073","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-41125","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-41082","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-37969","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-22047","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-26904","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-21919","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-22718","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-24521","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-1040","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-21999","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-20701","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-41379","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-23131","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-36934","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-42321","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2019-13608","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2019-11634","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-22894","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-22899","state":"mapped","mapping_types":["exploitation_technique"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}