Cloud Account

T1136.003

Sub-technique of T1136 Create Account.View on attack.mitre.org

About this technique

Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system.

In addition to user accounts, cloud accounts may be associated with services. Cloud providers handle the concept of service accounts in different ways. In Azure, service accounts include service principals and managed identities, which can be linked to various resources such as OAuth applications, serverless functions, and virtual machines in order to grant those resources permissions to perform various activities in the environment. In GCP, service accounts can also be linked to specific resources, as well as be impersonated by other accounts for Temporary Elevated Cloud Access. While AWS has no specific concept of service accounts, resources can be directly granted permission to assume roles.

Adversaries may create accounts that only have access to specific cloud services, which can reduce the chance of detection.

Once an adversary has created a cloud account, they can then manipulate that account to ensure persistence and allow access to additional resources - for example, by adding Additional Cloud Credentials or assigning Additional Cloud Roles.

Detection rules23

Rules on DetectionCode tagged with T1136.003.

Sigma3

RuleLevelLog source
New Federated Domain Added - Exchangemediumm365 / NULL
AWS ElastiCache Security Group Createdlowaws / NULL
New Github Organization Member Addedinformationalgithub / NULL

Splunk20

RuleTypeRiskData source
ASL AWS Create Access KeyHuntingNULLASL AWS CloudTrail
ASL AWS UpdateLoginProfileTTPNULLASL AWS CloudTrail
AWS CreateAccessKeyHuntingNULLAWS CloudTrail CreateAccessKey
AWS CreateLoginProfileTTPNULLAWS CloudTrail CreateLoginProfile AND AWS CloudTrail ConsoleLogin
AWS UpdateLoginProfileTTPNULLAWS CloudTrail UpdateLoginProfile
Azure AD External Guest User InvitedTTPNULLAzure Active Directory Invite external user
Azure AD Multiple Service Principals Created by SPAnomalyNULLAzure Active Directory Add service principal
Azure AD Multiple Service Principals Created by UserAnomalyNULLAzure Active Directory Add service principal
Azure AD Service Principal CreatedTTPNULLAzure Active Directory Add service principal
Azure Automation Account CreatedTTPNULLAzure Audit Create or Update an Azure Automation account
Azure Automation Runbook CreatedTTPNULLAzure Audit Create or Update an Azure Automation Runbook
O365 Add App Role Assignment Grant UserTTPNULLO365 Add app role assignment grant to user.
O365 Added Service PrincipalTTPNULLO365
O365 External Guest User InvitedTTPNULLOffice 365 Universal Audit Log
O365 External Identity Policy ChangedTTPNULLOffice 365 Universal Audit Log

Groups2

Software1

Campaigns0

None recorded.

Procedure examples3

Groups2

Used byProcedure example
GroupAPT29

APT29 can create new users through Azure AD.

GroupLAPSUS$

LAPSUS$ has created global admin accounts in the targeted organization's cloud instances to gain persistence.

Software1

Used byProcedure example
ToolAADInternals

AADInternals can create new Azure AD users.

References9

  1. AWS Create IAM User Open source
    AWS. (n.d.). Creating an IAM User in Your AWS Account. Retrieved January 29, 2020.
  2. AWS Instance Profiles Open source
    AWS. (n.d.). Using instance profiles. Retrieved February 28, 2024.
  3. AWS Lambda Execution Role Open source
    AWS. (n.d.). Lambda execution role. Retrieved February 28, 2024.
  4. GCP Create Cloud Identity Users Open source
    Google. (n.d.). Create Cloud Identity user accounts. Retrieved January 29, 2020.
  5. GCP Service Accounts Open source
    Google. (n.d.). Service Accounts Overview. Retrieved February 28, 2024.
  6. Microsoft Azure AD Users Open source
    Microsoft. (2019, November 11). Add or delete users using Azure Active Directory. Retrieved January 30, 2020.
  7. Microsoft Entra ID Service Principals Open source
    Microsoft. (2023, December 15). Application and service principal objects in Microsoft Entra ID. Retrieved February 28, 2024.
  8. Microsoft O365 Admin Roles Open source
    Ako-Adjei, K., Dickhaus, M., Baumgartner, P., Faigel, D., et. al.. (2019, October 8). About admin roles. Retrieved October 18, 2019.
  9. Microsoft Support O365 Add Another Admin, October 2019 Open source
    Microsoft. (n.d.). Add Another Admin. Retrieved October 18, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.