Sub-technique of T1087 Account Discovery.View on attack.mitre.org
Adversaries may attempt to get a listing of cloud accounts. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application.
With authenticated access there are several tools that can be used to find accounts. The Get-MsolRoleMember PowerShell cmdlet can be used to obtain account names given a role or permissions group in Office 365. The Azure CLI (AZ CLI) also provides an interface to obtain user accounts with authenticated access to a domain. The command az ad user list will list all users within a domain.
The AWS command aws iam list-users may be used to obtain a list of users in the current account while aws iam list-roles can obtain IAM roles that have a specified path prefix. In GCP, gcloud iam service-accounts list and gcloud projects get-iam-policy may be used to obtain a listing of service accounts and users in a project.
Rules on DetectionCode tagged with T1087.004.
| Rule | Level | Log source |
|---|---|---|
| Discovery Using AzureHound | high | azure / NULL |
| AWS STS GetCallerIdentity Enumeration Via TruffleHog | medium | aws / NULL |
| RBAC Permission Enumeration Attempt | low | kubernetes / application |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Azure AD AzureHound UserAgent Detected | TTP | NULL | Azure Active Directory NonInteractiveUserSignInLogs, Azure Active Directory MicrosoftGraphActivityLogs |
| Azure AD Service Principal Enumeration | TTP | NULL | Azure Active Directory MicrosoftGraphActivityLogs |
| Okta IDP Lifecycle Modifications | Anomaly | NULL | Okta |
| Okta Unauthorized Access to Application | Anomaly | NULL | Okta |
| Used by | Procedure example |
|---|---|
| GroupAPT29 | APT29 has conducted enumeration of Azure AD accounts. |
| GroupStorm-0501 | Storm-0501 has conducted enumeration of users, roles, and resources within victim Azure tenants using the tool Azurehound. |
| Used by | Procedure example |
|---|---|
| ToolAADInternals | AADInternals can enumerate Azure AD users. |
| MalwareMini Shai-Hulud | Mini Shai-Hulud has enumerated cloud accounts and subscriptions accessible to the targeted identity. |
| ToolPacu | Pacu can enumerate IAM users, roles, and groups. |
| ToolROADTools | ROADTools can enumerate Azure AD users. |
| Used by | Procedure example |
|---|---|
| CampaignC0027 | During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and to identify privileged users, along with the email addresses and AD attributes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.