Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0386 — Cloud Account Enumeration via API, CLI, and Scripting Interfaces
DET0386

Cloud Account Enumeration via API, CLI, and Scripting Interfaces

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN1087 Analytic 1087
Identity Provider

Enumeration of identity roles and users via API calls such as `Get-MsolRoleMember`, `az ad user list`, or Graph API tokens from unauthorized users or automation accounts.

Microsoft Entra ID Audit Logs RoleManagement.Read.Directory or Directory.Read.All azure:signinlogs Interactive/Non-Interactive Sign-In m365:defender Activity Log: Command Invocation
[TokenScope] Flags excessive or abnormal use of directory read scopes by unexpected principals.
[AppContext] Differentiate authorized automation from rogue access tokens or external tools.
[TimeWindow] Trigger correlation across short bursts of high-volume enumeration.
AN1088 Analytic 1088
IaaS

Use of AWS CLI (`aws iam list-users`, `list-roles`), Azure CLI (`az ad user list`), or GCP CLI (`gcloud iam service-accounts list`) from endpoints or cloud shells where such activity is unexpected.

AWS:CloudTrail AWS IAM: ListUsers, ListRoles azure:activity Azure CLI Operation: Microsoft.Graph/users/read
[CallerType] Suppress known admin accounts and alert on developer/test/service identities.
[CLIUserAgent] Correlate unexpected CLI user-agents and geolocation anomalies.
[CloudRegion] Suppress noise from known IP ranges or whitelisted accounts per region.
AN1089 Analytic 1089
Office Suite

Bulk enumeration of cloud user email identities through `Get-Recipient`, `Get-Mailbox`, `Get-User`, or Graph API directory listings by abnormal accounts or suspicious sessions.

WinEventLog:PowerShell CmdletName: Get-Recipient, Get-User Microsoft Graph API Logs users.list, directoryObjects.getByIds
[CmdletVolume] Tune threshold for recipient/mailbox queries by volume per hour.
[UserAgent] Match known admin consoles and exclude sanctioned tools like MSOL PowerShell.
[SessionContext] Elevate sessions from unmanaged or external endpoints.
AN1090 Analytic 1090
SaaS

Access to organizational directories via Google Workspace Directory API, Slack SCIM, or Okta SCIM by apps or identities outside normal roles.

Google Admin Audit users.list, groups.list saas:okta System API Call: user.read, group.read
[APIRequestRate] Detect rapid enumeration attempts or recursive group expansion.
[AppIntegrationID] Tag expected SCIM clients and suppress false positives from enterprise sync tools.
[GeoContext] Trigger alerts if enumeration occurs from anomalous IPs or regions.

Detected Techniques

1

Details

MITRE ID
DET0386
STIX ID
x-mitre-detection-strategy--880c0a88-bbd5-4d71-b8bd-72fbab7d58b2
Analytics
4
Techniques Detected
1
By Tactic
Discovery
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.