Sub-technique of T1136 Create Account.View on attack.mitre.org
Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system.
In addition to user accounts, cloud accounts may be associated with services. Cloud providers handle the concept of service accounts in different ways. In Azure, service accounts include service principals and managed identities, which can be linked to various resources such as OAuth applications, serverless functions, and virtual machines in order to grant those resources permissions to perform various activities in the environment. In GCP, service accounts can also be linked to specific resources, as well as be impersonated by other accounts for Temporary Elevated Cloud Access. While AWS has no specific concept of service accounts, resources can be directly granted permission to assume roles.
Adversaries may create accounts that only have access to specific cloud services, which can reduce the chance of detection.
Once an adversary has created a cloud account, they can then manipulate that account to ensure persistence and allow access to additional resources - for example, by adding Additional Cloud Credentials or assigning Additional Cloud Roles.
Rules on DetectionCode tagged with T1136.003.
| Rule | Level | Log source |
|---|---|---|
| New Federated Domain Added - Exchange | medium | m365 / NULL |
| AWS ElastiCache Security Group Created | low | aws / NULL |
| New Github Organization Member Added | informational | github / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| ASL AWS Create Access Key | Hunting | NULL | ASL AWS CloudTrail |
| ASL AWS UpdateLoginProfile | TTP | NULL | ASL AWS CloudTrail |
| AWS CreateAccessKey | Hunting | NULL | AWS CloudTrail CreateAccessKey |
| AWS CreateLoginProfile | TTP | NULL | AWS CloudTrail CreateLoginProfile AND AWS CloudTrail ConsoleLogin |
| AWS UpdateLoginProfile | TTP | NULL | AWS CloudTrail UpdateLoginProfile |
| Azure AD External Guest User Invited | TTP | NULL | Azure Active Directory Invite external user |
| Azure AD Multiple Service Principals Created by SP | Anomaly | NULL | Azure Active Directory Add service principal |
| Azure AD Multiple Service Principals Created by User | Anomaly | NULL | Azure Active Directory Add service principal |
| Azure AD Service Principal Created | TTP | NULL | Azure Active Directory Add service principal |
| Azure Automation Account Created | TTP | NULL | Azure Audit Create or Update an Azure Automation account |
| Azure Automation Runbook Created | TTP | NULL | Azure Audit Create or Update an Azure Automation Runbook |
| O365 Add App Role Assignment Grant User | TTP | NULL | O365 Add app role assignment grant to user. |
| O365 Added Service Principal | TTP | NULL | O365 |
| O365 External Guest User Invited | TTP | NULL | Office 365 Universal Audit Log |
| O365 External Identity Policy Changed | TTP | NULL | Office 365 Universal Audit Log |
| O365 Multiple Service Principals Created by SP | Anomaly | NULL | O365 Add service principal. |
| O365 Multiple Service Principals Created by User | Anomaly | NULL | O365 Add service principal. |
| O365 New Federated Domain Added | TTP | NULL | O365 |
| O365 SharePoint Allowed Domains Policy Changed | TTP | NULL | Office 365 Universal Audit Log |
| Windows Azure PowerShell Module Installation Via PowerShell Script | Anomaly | NULL | Powershell Script Block Logging 4104 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT29 | APT29 can create new users through Azure AD. |
| GroupLAPSUS$ | LAPSUS$ has created global admin accounts in the targeted organization's cloud instances to gain persistence. |
| Used by | Procedure example |
|---|---|
| ToolAADInternals | AADInternals can create new Azure AD users. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.