| ASL AWS IAM Delete Policy | Hunting | NULL | ASL AWS CloudTrail | T1098 |
| ASL AWS IAM Failure Group Deletion | Anomaly | NULL | ASL AWS CloudTrail | T1098 |
| ASL AWS IAM Successful Group Deletion | Hunting | NULL | ASL AWS CloudTrail | T1098 |
| AWS IAM Delete Policy | Hunting | NULL | AWS CloudTrail DeletePolicy | T1098 |
| AWS IAM Failure Group Deletion | Anomaly | NULL | AWS CloudTrail DeleteGroup | T1098 |
| AWS IAM Successful Group Deletion | Hunting | NULL | AWS CloudTrail DeleteGroup | T1098 |
| Azure AD Admin Consent Bypassed by Service Principal | TTP | NULL | Azure Active Directory Add app role assignment to service principal | T1098.003 |
| Azure AD Application Administrator Role Assigned | TTP | NULL | Azure Active Directory Add member to role | T1098.003 |
| Azure AD FullAccessAsApp Permission Assigned | TTP | NULL | Azure Active Directory Update application | T1098.002 T1098.003 |
| Azure AD Global Administrator Role Assigned | TTP | NULL | Azure Active Directory Add member to role | T1098.003 |
| Azure AD New MFA Method Registered | TTP | NULL | Azure Active Directory Update user | T1098.005 |
| Azure AD PIM Role Assigned | TTP | NULL | Azure Active Directory | T1098.003 |
| Azure AD PIM Role Assignment Activated | TTP | NULL | Azure Active Directory | T1098.003 |
| Azure AD Privileged Role Assigned | TTP | NULL | Azure Active Directory Add member to role | T1098.003 |
| Azure AD Privileged Role Assigned to Service Principal | TTP | NULL | Azure Active Directory Add member to role | T1098.003 |
| Azure AD Service Principal New Client Credentials | TTP | NULL | Azure Active Directory | T1098.001 |
| Azure AD Service Principal Owner Added | TTP | NULL | Azure Active Directory Add owner to application | T1098 |
| Azure AD Service Principal Privilege Escalation | TTP | NULL | Azure Active Directory Add app role assignment to service principal | T1098.003 |
| Azure AD Tenant Wide Admin Consent Granted | TTP | NULL | Azure Active Directory Consent to application | T1098.003 |
| Azure AD User Enabled And Password Reset | TTP | NULL | Azure Active Directory Enable account, Azure Active Directory Reset password (by admin), Azure Active Directory Update user | T1098 |
| Azure AD User ImmutableId Attribute Updated | TTP | NULL | Azure Active Directory Update user | T1098 |
| Cisco ASA - User Privilege Level Change | Anomaly | NULL | Cisco ASA Logs | T1098 |
| Cisco Configuration Archive Logging Analysis | Hunting | NULL | Cisco IOS Logs | T1098 |
| ESXi Account Modified | Anomaly | NULL | VMWare ESXi Syslog | T1098 |
| ESXi User Granted Admin Role | TTP | NULL | VMWare ESXi Syslog | T1098 |
| Linux Auditd Possible Access Or Modification Of Sshd Config File | Anomaly | NULL | Linux Auditd Path, Linux Auditd Cwd | T1098.004 |
| Linux Possible Access Or Modification Of sshd Config File | Anomaly | NULL | Sysmon for Linux EventID 1 | T1098.004 |
| Linux Possible Ssh Key File Creation | Anomaly | NULL | Sysmon for Linux EventID 11 | T1098.004 |
| Linux SSH Authorized Keys Modification | Anomaly | NULL | Sysmon for Linux EventID 1 | T1098.004 |
| Linux Usermod Root UID Set | TTP | NULL | Sysmon for Linux EventID 1 | T1098 |
| O365 Admin Consent Bypassed by Service Principal | TTP | NULL | O365 Add app role assignment to service principal. | T1098.003 |
| O365 Application Available To Other Tenants | TTP | NULL | Office 365 Universal Audit Log | T1098.003 |
| O365 Application Registration Owner Added | TTP | NULL | O365 Add owner to application. | T1098 |
| O365 ApplicationImpersonation Role Assigned | TTP | NULL | O365 | T1098.002 |
| O365 Elevated Mailbox Permission Assigned | TTP | NULL | O365 Add-MailboxPermission | T1098.002 |
| O365 FullAccessAsApp Permission Assigned | TTP | NULL | O365 Update application. | T1098.002 T1098.003 |
| O365 High Privilege Role Granted | TTP | NULL | O365 Add member to role. | T1098.003 |
| O365 Mailbox Folder Read Permission Assigned | TTP | NULL | O365 ModifyFolderPermissions | T1098.002 |
| O365 Mailbox Folder Read Permission Granted | TTP | NULL | O365 ModifyFolderPermissions | T1098.002 |
| O365 Mailbox Read Access Granted to Application | TTP | NULL | O365 Update application. | T1098.003 |
| O365 New MFA Method Registered | TTP | NULL | O365 Update user. | T1098.005 |
| O365 Privileged Role Assigned | TTP | NULL | Office 365 Universal Audit Log | T1098.003 |
| O365 Privileged Role Assigned To Service Principal | TTP | NULL | Office 365 Universal Audit Log | T1098.003 |
| O365 Service Principal New Client Credentials | TTP | NULL | O365 | T1098.001 |
| O365 Service Principal Privilege Escalation | TTP | NULL | O365 Add app role assignment grant to user. | T1098.003 |
| O365 Suspicious Rights Delegation | TTP | NULL | | T1098.002 |
| O365 Tenant Wide Admin Consent Granted | TTP | NULL | O365 Consent to application. | T1098.003 |
| Okta New Device Enrolled on Account | TTP | NULL | Okta | T1098.005 |
| PingID Mismatch Auth Source and Verification Response | TTP | NULL | PingID | T1098.005 |
| PingID New MFA Method After Credential Reset | TTP | NULL | PingID | T1098.005 |
| PingID New MFA Method Registered For User | TTP | NULL | PingID | T1098.005 |
| Windows AD add Self to Group | TTP | NULL | Windows Event Log Security 4728 | T1098 |
| Windows AD DSRM Account Changes | TTP | NULL | Sysmon EventID 13 | T1098 |
| Windows AD DSRM Password Reset | TTP | NULL | Windows Event Log Security 4794 | T1098 |
| Windows AD Privileged Group Modification | TTP | NULL | Windows Event Log Security 4728 | T1098 |
| Windows AD Self DACL Assignment | TTP | NULL | Windows Event Log Security 5136 | T1098 |
| Windows AD ServicePrincipalName Added To Domain Account | TTP | NULL | Windows Event Log Security 5136 | T1098 |
| Windows AD Short Lived Domain Account ServicePrincipalName | TTP | NULL | Windows Event Log Security 5136 | T1098 |
| Windows Azure PowerShell Module Installation Via PowerShell Script | Anomaly | NULL | Powershell Script Block Logging 4104 | T1098 |
| Windows DnsAdmins New Member Added | TTP | NULL | Windows Event Log Security 4732 | T1098 |
| Windows Entra User Management Via Azure CLI | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1098 |
| Windows Increase in Group or Object Modification Activity | TTP | NULL | Windows Event Log Security 4663 | T1098 |
| Windows Increase in User Modification Activity | TTP | NULL | Windows Event Log Security 4720 | T1098 |
| Windows Multiple Account Passwords Changed | TTP | NULL | Windows Event Log Security 4724 | T1098 |
| Windows Multiple Accounts Deleted | TTP | NULL | Windows Event Log Security 4726 | T1098 |
| Windows Multiple Accounts Disabled | TTP | NULL | Windows Event Log Security 4725 | T1098 |