Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0013 — User Account Metadata
DC0013

User Account Metadata

33 analytic(s) · 20 detection strategy(ies)

Description

Contextual data about an account, which may include a username, user ID, environmental data, etc.

Referenced in Analytics

33
AN0383 Analytic 0383 DET0136

Detection of unauthorized modification of Active Directory SID-History attributes to escalate privileges. This chain involves: (1) privileged operations or API calls to DsAddSidHistory or related AD modification functions, (2) observed attribute changes in SID-History (Event ID 5136), (3) new logon sessions where the token includes unexpected or privileged SID-History values, and (4) follow-on resource access using elevated privileges derived from SID-History injection.

WinEventLog:Security WinEventLog:Security etw:Microsoft-Windows-Directory-Services-SAM
AN0384 Analytic 0384 DET0137

Unusual direct disk access attempts (e.g., use of \\.\PhysicalDrive notation), abnormal writes to MBR/boot sectors, and installation of kernel drivers that grant raw disk access. Correlate anomalous process creation with disk modification attempts and driver loads.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0417 Analytic 0417 DET0147

Adversary gains access to cloud-hosted services such as AWS SES, SNS, or OpenAI API, enables or modifies usage policies, and initiates resource-intensive actions (e.g., mass email/SMS or LLM queries), often from unauthorized regions or under anomalous identity conditions.

AWS:CloudTrail AWS:CloudTrail AWS:CloudTrail
AN0456 Analytic 0456 DET0161

Chain: (1) interactive/non-interactive `chage -l`, `grep`/`cat` of PAM config (e.g., `/etc/pam.d/common-password`, `/etc/security/pwquality.conf`); (2) optional reads of `/etc/login.defs`; (3) same user performs account enumeration or password change attempts shortly after. Use auditd `execve` and file read events plus shell history collection.

auditd:SYSCALL auditd:SYSCALL linux:syslog
AN0457 Analytic 0457 DET0161

Chain: (1) execution of `pwpolicy` or MDM/DirectoryService reads of account policies; (2) optional read of `/Library/Preferences/com.apple.loginwindow` or config profiles; (3) follow-on credential probing or lateral movement by same user/session. Use unified logs and process telemetry.

macos:unifiedlog macos:unifiedlog macos:MDM
AN0458 Analytic 0458 DET0161

Chain: (1) cloud API calls that fetch tenant/organization password policy (e.g., AWS `GetAccountPasswordPolicy`, GCP/OCI equivalents or IAM settings reads); (2) within a short window, the same principal creates users, rotates creds, or changes auth settings. Use cloud audit logs.

AWS:CloudTrail
AN0459 Analytic 0459 DET0161

Chain: (1) IdP policy/read operations by a principal (e.g., Microsoft Entra/Graph requests to read password or authentication policies); (2) adjacent risky changes (role assignment, app consent) by same principal. Use IdP audit logs.

azure:audit
AN0460 Analytic 0460 DET0161

Chain: (1) SaaS admin API or PowerShell remote session reads tenant password/authentication settings (e.g., M365 Unified Audit Log ‘Cmdlet’ with `Get-MsolPasswordPolicy`/`Get-OrganizationConfig` parameters that expose password settings); (2) same session proceeds to mailbox or tenant changes.

m365:unified
AN0501 Analytic 0501 DET0176

Post-compromise identity & session anomalies that follow a drive-by compromise: token reuse from new/unfamiliar IPs, anomalous sign-in patterns for previously inactive users, unexpected consent/grant events, or provisioning changes. Defender sees an endpoint/browser compromise (network + endpoint signals) followed by unusual IdP events: new refresh token issuance, consent/consent-grant events, odd MFA bypass patterns, or unusual OAuth client registrations.

azure:signinlogs m365:unified saas:auth AWS:CloudTrail
AN0642 Analytic 0642 DET0229

Suspicious querying of organization-wide directory data via Google Workspace Directory API or Outlook GAL sync in high volume from abnormal users, service accounts, or unknown device contexts.

gcp:audit m365:unified azure:signinlogs
AN0690 Analytic 0690 DET0247

Detects creation of cloud instances, services, or resources in normally unused or unsupported regions, especially following initial account access or credential use from known regions. Correlates resource provisioning across regions with absence of historical usage and alerting from standard logging services (e.g., GuardDuty not enabled in that region).

AWS:CloudTrail AWS:CloudTrail CloudTrail:GetCallerIdentity AWS:VPCFlowLogs
AN0827 Analytic 0827 DET0297

Processes attempting raw disk access to overwrite sensitive structures such as the MBR or partition table using \\.\PhysicalDrive notation. Detection relies on correlating process creation, privilege escalation, and raw sector writes in Sysmon and Security logs.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0849 Analytic 0849 DET0303

Enumeration of local ESXi accounts using esxcli or vSphere API from unauthorized sessions.

vpxd.log esxi:shell
AN0882 Analytic 0882 DET0316

Processes attempting raw disk access via \\.\PhysicalDrive paths, abnormal file I/O to MBR/boot sectors, or loading of third-party drivers (e.g., RawDisk) that enable disk overwrite. Correlate process creation, privilege usage, and disk modification events within a short time window.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0958 Analytic 0958 DET0338

Container process uses mounted cloud credentials or token cache to authenticate without known orchestration.

docker:runtime AWS:CloudTrail
AN0960 Analytic 0960 DET0338

Use of instance metadata tokens across instances or misuse of short-lived tokens issued for different roles.

AWS:CloudTrail AWS:CloudTrail
AN1003 Analytic 1003 DET0353

User creation or modification via dscl with IsHidden=1, UID<500, or plist edits to com.apple.loginwindow Hide500Users flag. Defender view: correlation of hidden account attributes with login screen exclusion.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1030 Analytic 1030 DET0363

A non-privileged or abnormal process attempts to open a handle with full access (0x1F0FFF) to lsass.exe and subsequently invokes memory dump, file creation, or registry modification indicative of credential scraping. This behavior chain reflects staged credential theft activity.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security WinEventLog:Sysmon
AN1077 Analytic 1077 DET0383

Detects adversary behavior where a newly created or renamed user account closely resembles existing service or administrator accounts to blend in and avoid detection. Common patterns include prefix/suffix modifications, homoglyphs, or use of names like 'admin1', 'adm1n', or 'backup_help'.

WinEventLog:Security windows:osquery
AN1078 Analytic 1078 DET0383

Detects creation or renaming of accounts with names that closely match known service, root, or admin accounts. Behavior often follows account discovery or deletion, attempting to blend into system activity logs using trusted name conventions.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN1079 Analytic 1079 DET0383

Detects adversary creation of cloud or IdP accounts whose names resemble existing privileged or service accounts. May indicate preparation for privilege escalation or defense evasion.

azure:audit azure:audit saas:okta
AN1087 Analytic 1087 DET0386

Enumeration of identity roles and users via API calls such as `Get-MsolRoleMember`, `az ad user list`, or Graph API tokens from unauthorized users or automation accounts.

Microsoft Entra ID Audit Logs azure:signinlogs m365:defender
AN1088 Analytic 1088 DET0386

Use of AWS CLI (`aws iam list-users`, `list-roles`), Azure CLI (`az ad user list`), or GCP CLI (`gcloud iam service-accounts list`) from endpoints or cloud shells where such activity is unexpected.

AWS:CloudTrail azure:activity
AN1089 Analytic 1089 DET0386

Bulk enumeration of cloud user email identities through `Get-Recipient`, `Get-Mailbox`, `Get-User`, or Graph API directory listings by abnormal accounts or suspicious sessions.

WinEventLog:PowerShell Microsoft Graph API Logs
AN1090 Analytic 1090 DET0386

Access to organizational directories via Google Workspace Directory API, Slack SCIM, or Okta SCIM by apps or identities outside normal roles.

Google Admin Audit saas:okta
AN1105 Analytic 1105 DET0393

Multiple AWS CloudTrail events indicating temporary privilege escalation via PassRole and AssumeRole targeting newly created services or non-interactive infrastructure.

AWS:CloudTrail
AN1106 Analytic 1106 DET0393

Token creation or access delegation where a user impersonates a higher-privileged service account or performs domain-wide delegation actions, such as GCP's serviceAccountTokenCreator or Workspace impersonation.

gcp:iam gcp:workspaceaudit
AN1127 Analytic 1127 DET0402

Unusual enumeration of services and resources through cloud APIs such as AWS CLI `describe-*`, Azure Resource Manager queries, or GCP project listings. Defender perspective includes anomalous API calls, unexpected volume of service enumeration, and correlation of discovery with recently compromised sessions.

AWS:CloudTrail AWS:CloudTrail
AN1328 Analytic 1328 DET0484

Spike in object access from new IAM user or role followed by data exfiltration to external IPs

AWS:CloudTrail AWS:CloudTrail AWS:VPCFlowLogs
AN1398 Analytic 1398 DET0507

Adversary gains high integrity or special privileges (e.g., SeDebugPrivilege), locates a running browser process, opens it with write/inject rights, and modifies it (e.g., CreateRemoteThread / DLL load) to inherit cookies/tokens or establish a browser pivot. Optional step: create a new logon session or use explicit credentials, then drive the victim browser to intranet resources.

WinEventLog:Security WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1614 Analytic 1614 DET0587

Detection of account enumeration through directory service queries or system utilities accessing account metadata stores, followed by structured enumeration output.

macos:unifiedlog macos:unifiedlog
AN1616 Analytic 1616 DET0587

Detection of identity directory enumeration through API calls or administrative queries retrieving multiple account objects within a short interval.

azure:signinlogs saas:okta
AN1618 Analytic 1618 DET0587

Account enumeration via bulk access to user directory features or hidden APIs.

gcp:audit

Detection Strategies

20
DET0136 Behavior-chain detection for T1134.005 Access Token Manipulation: SID-History Injection (Windows) DET0137 Detection Strategy for Disk Wipe via Direct Disk Access and Destructive Commands DET0147 Detection Strategy for Cloud Service Hijacking via SaaS Abuse DET0161 Password Policy Discovery – cross-platform behavior-chain analytics DET0176 Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189) DET0229 Enumeration of Global Address Lists via Email Account Discovery DET0247 Detection of Adversary Use of Unused or Unsupported Cloud Regions (IaaS) DET0297 Detection Strategy for Disk Structure Wipe via Boot/Partition Overwrite DET0303 Local Account Enumeration Across Host Platforms DET0316 Detection Strategy for Disk Content Wipe via Direct Access and Overwrite DET0338 Behavioral Detection Strategy for Use Alternate Authentication Material (T1550) DET0353 Detection Strategy for Hidden User Accounts DET0363 Detection of Credential Dumping from LSASS Memory via Access and Dump Sequence DET0383 Detection Strategy for Masquerading via Account Name Similarity DET0386 Cloud Account Enumeration via API, CLI, and Scripting Interfaces DET0393 Detection Strategy for Temporary Elevated Cloud Access Abuse (T1548.005) DET0402 Detection Strategy for Cloud Service Discovery DET0484 Multi-Platform Cloud Storage Exfiltration Behavior Chain DET0507 Detect browser session hijacking via privilege, handle access, and remote thread into browsers DET0587 Enumeration of User or Account Information Across Platforms

Details

MITRE ID
DC0013
STIX ID
x-mitre-data-component--b5d0492b-cda4-421c-8e51-ed2b8d85c5d0
Analytics
33
Detection Strategies
20
Leaving Threaticon

This link opens an external site that isn't part of the platform.