Cloud Account

T1087.004

Sub-technique of T1087 Account Discovery.View on attack.mitre.org

About this technique

Adversaries may attempt to get a listing of cloud accounts. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application.

With authenticated access there are several tools that can be used to find accounts. The Get-MsolRoleMember PowerShell cmdlet can be used to obtain account names given a role or permissions group in Office 365. The Azure CLI (AZ CLI) also provides an interface to obtain user accounts with authenticated access to a domain. The command az ad user list will list all users within a domain.

The AWS command aws iam list-users may be used to obtain a list of users in the current account while aws iam list-roles can obtain IAM roles that have a specified path prefix. In GCP, gcloud iam service-accounts list and gcloud projects get-iam-policy may be used to obtain a listing of service accounts and users in a project.

Detection rules7

Rules on DetectionCode tagged with T1087.004.

Sigma3

RuleLevelLog source
Discovery Using AzureHoundhighazure / NULL
AWS STS GetCallerIdentity Enumeration Via TruffleHogmediumaws / NULL
RBAC Permission Enumeration Attemptlowkubernetes / application

Splunk4

RuleTypeRiskData source
Azure AD AzureHound UserAgent DetectedTTPNULLAzure Active Directory NonInteractiveUserSignInLogs, Azure Active Directory MicrosoftGraphActivityLogs
Azure AD Service Principal EnumerationTTPNULLAzure Active Directory MicrosoftGraphActivityLogs
Okta IDP Lifecycle ModificationsAnomalyNULLOkta
Okta Unauthorized Access to ApplicationAnomalyNULLOkta

Groups2

Software4

Campaigns1

Procedure examples7

Groups2

Used byProcedure example
GroupAPT29

APT29 has conducted enumeration of Azure AD accounts.

GroupStorm-0501

Storm-0501 has conducted enumeration of users, roles, and resources within victim Azure tenants using the tool Azurehound.

Software4

Used byProcedure example
ToolAADInternals

AADInternals can enumerate Azure AD users.

MalwareMini Shai-Hulud

Mini Shai-Hulud has enumerated cloud accounts and subscriptions accessible to the targeted identity.

ToolPacu

Pacu can enumerate IAM users, roles, and groups.

ToolROADTools

ROADTools can enumerate Azure AD users.

Campaigns1

Used byProcedure example
CampaignC0027

During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and to identify privileged users, along with the email addresses and AD attributes.

References7

  1. AWS List Roles Open source
    Amazon. (n.d.). List Roles. Retrieved August 11, 2020.
  2. AWS List Users Open source
    Amazon. (n.d.). List Users. Retrieved August 11, 2020.
  3. Black Hills Red Teaming MS AD Azure, 2018 Open source
    Felch, M.. (2018, August 31). Red Teaming Microsoft Part 1 Active Directory Leaks via Azure. Retrieved October 6, 2019.
  4. GitHub Raindance Open source
    Stringer, M.. (2018, November 21). RainDance. Retrieved October 6, 2019.
  5. Google Cloud - IAM Servie Accounts List API Open source
    Google. (2020, June 23). gcloud iam service-accounts list. Retrieved August 4, 2020.
  6. Microsoft AZ CLI Open source
    Microsoft. (n.d.). az ad user. Retrieved October 6, 2019.
  7. Microsoft msolrolemember Open source
    Microsoft. (n.d.). Get-MsolRoleMember. Retrieved October 6, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.