{"id":"T1586.003","name":"Cloud Accounts","url":"https://attack.mitre.org/techniques/T1586/003","tactics":["resource-development"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0879","stix_id":"x-mitre-detection-strategy--df374bac-bd69-4351-be3f-1bd863c429ad","name":"Detection of Cloud Accounts","url":"https://attack.mitre.org/detectionstrategies/DET0879","analytics":[{"id":"AN2011","stix_id":"x-mitre-analytic--cce3f1e3-a688-4519-bd9b-0ec5ba57bc11","name":"Analytic 2011","description":"Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during exfiltration (ex: [Transfer Data to Cloud Account](https://attack.mitre.org/techniques/T1537)).","url":"https://attack.mitre.org/detectionstrategies/DET0879#AN2011","platforms":["PRE"],"log_source_references":[],"mutable_elements":[],"live":true,"detection_strategies":["DET0879"],"techniques":["T1586.003"]}],"live":true,"version":"1.0","techniques":["T1586.003"]}],"sigma_rules":[{"id":"07e97cc6-aed1-43ae-9081-b3470d2367f1","title":"Okta Suspicious Activity Reported by End-user","author":"kelnage","status":"test","level":"high","date":"2023-09-07","modified":"2026-04-27","description":"Detects when an Okta end-user reports activity by their account as being potentially suspicious.","references":["https://developer.okta.com/docs/reference/api/system-log/","https://github.com/okta/workflows-templates/blob/1164f0eb71ce47c9ddc7d850e9ab87b5a2b42333/workflows/suspicious_activity_reported/readme.md"],"logsource":{"product":"okta","service":"okta"},"tags":["attack.resource-development","attack.t1586.003"],"path":"rules/identity/okta/okta_suspicious_activity_enduser_report.yml","techniques":["T1586.003"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}