Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0010 — User Account Modification
DC0010

User Account Modification

36 analytic(s) · 20 detection strategy(ies)

Description

Changes made to an existing user, service, or machine account, including alterations to attributes, permissions, roles, authentication methods, or group memberships.

Referenced in Analytics

36
AN0103 Analytic 0103 DET0036

Adversary registers new devices to compromised user accounts to bypass MFA or conditional access policies via Azure Entra ID, Okta, or Duo self-enrollment portals.

azure:audit ApplicationLog:EntraIDPortal azure:audit
AN0230 Analytic 0230 DET0082

Adversary leverages root or sudo access to alter system banners, web content directories (e.g., /var/www/html), or login configurations (/etc/issue). File creation or overwrites may coincide with suspicious script execution or cron job activity.

auditd:SYSCALL auditd:SYSCALL linux:syslog
AN0265 Analytic 0265 DET0096

Account attribute changes (e.g., password set, group membership, servicePrincipalName, logon hours) correlated with unusual process lineage or timing, indicating privilege escalation or persistence via valid accounts.

WinEventLog:Security WinEventLog:Sysmon
AN0266 Analytic 0266 DET0096

Use of native tools or scripting (e.g., `usermod`, `passwd`, `groupmod`) to escalate permissions or persist access on existing users, correlated with login or process events.

auditd:SYSCALL auditd:PATH
AN0267 Analytic 0267 DET0096

Modifications to user accounts via `dscl`, `pwpolicy`, or System Preferences CLI (`sysadminctl`) that alter user groups, enable root, or bypass MDM restrictions.

macos:unifiedlog
AN0268 Analytic 0268 DET0096

Modifications to SSO/SAML user attributes (e.g., `isAdmin`, `role`, MFA bypass, App assignments) often through CLI, API, or rogue IdP apps.

saas:okta
AN0270 Analytic 0270 DET0096

Role escalation (e.g., Editor → Owner) in cloud collaboration tools (Google Workspace, O365) or file sharing apps to maintain elevated access.

m365:unified
AN0290 Analytic 0290 DET0104

Detects suspicious configuration changes in IdP authentication flows such as enabling reversible password encryption, MFA bypass, or policy weakening. Correlates policy modification events with unusual administrative activity.

azure:policy m365:unified
AN0291 Analytic 0291 DET0104

Detects unauthorized changes to IAM authentication configurations such as disabling MFA, creating backdoor access keys, or altering trust policies. Correlates identity policy updates with unusual login behavior.

AWS:CloudTrail AWS:CloudTrail
AN0334 Analytic 0334 DET0120

Correlated user account modification (reset, disable, deletion) events with anomalous process lineage (e.g., PowerShell or net.exe from an interactive session), especially outside of IT admin change windows or by non-admin users.

WinEventLog:Security WinEventLog:Sysmon
AN0339 Analytic 0339 DET0120

Deletion or disablement of user accounts in platforms like Okta, Salesforce, or Zoom with anomalies in admin session attributes or mass actions within short duration.

saas:okta
AN0544 Analytic 0544 DET0190

Detects conditional access policy changes, exclusion of accounts from MFA enforcement, or registration of new MFA factors by non-admin or anomalous users.

azure:signinlogs m365:unified
AN0548 Analytic 0548 DET0190

Detects suspicious MFA method changes, such as registration of weaker factors (e.g., SMS), or removal of MFA requirements for specific accounts or groups.

saas:zoom
AN0771 Analytic 0771 DET0277

Detection of new IAM roles or policies attached to a user/service in AWS/GCP/Azure outside normal patterns or hours, often following account compromise.

AWS:CloudTrail
AN0772 Analytic 0772 DET0277

Behavioral chain of a user being granted elevated privileges or roles in Entra ID or Okta following suspicious login or account creation activity.

m365:audit
AN0773 Analytic 0773 DET0277

Detection of new admin or role assignment actions within Microsoft 365/O365 environments to elevate access for persistence or lateral movement.

m365:unified
AN0803 Analytic 0803 DET0289

Disabling mailbox or tenant-level audit logging, often using Set-MailboxAuditBypassAssociation or downgrading license tiers. Defender view: sudden absence of mailbox activity logging for monitored users.

m365:unified
AN0815 Analytic 0815 DET0293

Detects registration of new PTA agents, conditional access changes disabling hybrid MFA enforcement, or suspicious updates to AD FS token-signing configurations.

azure:signinlogs m365:unified
AN0854 Analytic 0854 DET0305

Adversary modifies GPO containers or files under SYSVOL using LDAP, ADSI, PowerShell (e.g., New-GPOImmediateTask) or GUI tools. This includes directory object changes (e.g., gPCFileSysPath), delegation assignments (SeEnableDelegationPrivilege), and SYSVOL file writes (ScheduledTasks.xml, GptTmpl.inf).

WinEventLog:Security WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0865 Analytic 0865 DET0310

Detects unauthorized additions of users or machine accounts to privileged local or domain groups (e.g., Administrators, Remote Desktop Users).

WinEventLog:Security
AN0866 Analytic 0866 DET0310

Detects unexpected use of usermod, gpasswd, or direct modification of /etc/group to elevate user group membership.

auditd:SYSCALL
AN0867 Analytic 0867 DET0310

Detects use of `dseditgroup` or `dscl` to add users to privileged macOS groups (e.g., admin).

macos:unifiedlog
AN0899 Analytic 0899 DET0319

Adversaries create user accounts via identity provider APIs or admin portals (e.g., Azure AD, Okta). These accounts may be assigned elevated privileges or used in chained authentication. Detection monitors Add User activity from suspicious IPs or automation sources, followed by role/permission escalation.

azure:audit azure:audit azure:signinlogs
AN0900 Analytic 0900 DET0319

Adversaries use cloud API, CLI, or console to create IAM users or roles. Initial CreateUser is followed by policy/role attachment. Detection monitors temporal chains involving IAM:CreateUser, AttachUserPolicy, and credential generation, especially from automation or foreign IP ranges.

AWS:CloudTrail AWS:CloudTrail
AN0978 Analytic 0978 DET0345

Monitor for unexpected privilege elevation operations via SAML assertion manipulation, role injection, or changes to identity mappings that result in access escalation.

azure:signinlogs
AN0979 Analytic 0979 DET0345

Detect sudden privilege escalations such as IAM role changes, user-assigned privilege boundaries, or elevation via assumed roles beyond normal behavior.

AWS:CloudTrail AWS:CloudTrail
AN1051 Analytic 1051 DET0373

Detection of anomalous or unauthorized mailbox delegation activity (e.g., Add-MailboxPermission, Default/Anonymous mailbox permissions, Gmail delegation setup).

m365:unified
AN1078 Analytic 1078 DET0383

Detects creation or renaming of accounts with names that closely match known service, root, or admin accounts. Behavior often follows account discovery or deletion, attempting to blend into system activity logs using trusted name conventions.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN1079 Analytic 1079 DET0383

Detects adversary creation of cloud or IdP accounts whose names resemble existing privileged or service accounts. May indicate preparation for privilege escalation or defense evasion.

azure:audit azure:audit saas:okta
AN1117 Analytic 1117 DET0398

Startup-based persistence mechanisms within Microsoft Office Suite like template macros and home page redirects being configured through internal automation or client-side settings.

m365:unified m365:mailboxaudit
AN1259 Analytic 1259 DET0458

Adversary modifies Active Directory domain trust settings via `netdom`, `nltest`, or PowerShell to add new domain trust or alter federation. Modifications occur in AD object attributes like trustDirection, trustType, trustAttributes, often paired with SeEnableDelegationPrivilege or certificate injection.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon
AN1469 Analytic 1469 DET0531

Addition of credentials (keys, app passwords, x.509 certs) to existing cloud accounts, service principals, or OAuth apps via portal or API by non-standard identities or IP ranges.

azure:audit
AN1470 Analytic 1470 DET0531

Cloud API usage to create/import SSH keys or generate new access keys (CreateAccessKey, ImportKeyPair, CreateLoginProfile) from non-console access or unusual principals.

AWS:CloudTrail gcp:audit
AN1471 Analytic 1471 DET0531

Credential-related configuration changes in productivity apps, such as API key creation in Google Workspace, app tokens in Slack, or user-level OAuth credentials in M365.

gcp:audit m365:unified
AN1579 Analytic 1579 DET0572

Detects assignment of high-privilege roles to user or service accounts via Kubernetes RoleBinding or ClusterRoleBinding objects, especially outside of CI/CD automation or from unknown IPs.

kubernetes:audit
AN1608 Analytic 1608 DET0583

Account creation via cloud service APIs or CLI, often associated with key generation. Monitored via CloudTrail or equivalent audit logs.

AWS:CloudTrail AWS:CloudTrail

Details

MITRE ID
DC0010
STIX ID
x-mitre-data-component--d27b0089-2c39-4b6c-84ff-303e48657e77
Analytics
36
Detection Strategies
20
Leaving Threaticon

This link opens an external site that isn't part of the platform.