Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0393 — Detection Strategy for Temporary Elevated Cloud Access Abuse (T1548.005)
DET0393

Detection Strategy for Temporary Elevated Cloud Access Abuse (T1548.005)

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN1105 Analytic 1105
IaaS

Multiple AWS CloudTrail events indicating temporary privilege escalation via PassRole and AssumeRole targeting newly created services or non-interactive infrastructure.

AWS:CloudTrail PassRole
[targetRoleName] Define which roles are allowed to be assumed or passed; restrict highly privileged roles.
[TimeWindow] Time range between PassRole and AssumeRole events to link the privilege chain.
[invokingService] Restrict which services are authorized to invoke role passing (e.g., Lambda, EC2).
AN1106 Analytic 1106
Identity Provider

Token creation or access delegation where a user impersonates a higher-privileged service account or performs domain-wide delegation actions, such as GCP's serviceAccountTokenCreator or Workspace impersonation.

gcp:iam PrincipalEmail with serviceAccountTokenCreator impersonating new identity gcp:workspaceaudit Token Generation via Domain Delegation
[userEmailFilter] Tune based on legitimate service accounts allowed to impersonate user accounts.
[delegatedScope] Limit delegated access to specific scopes relevant to business functions.
AN1107 Analytic 1107
Office Suite

Detection of ApplicationImpersonation role assignment or delegated mailbox access to service principals or rarely used users, especially outside of normal hours or geographic norms.

m365:unified Add-MailboxPermission or Set-ManagementRoleAssignment m365:signinlogs Unusual sign-in from service principal to user mailbox
[TargetMailbox] Mailbox of interest where impersonation or access delegation occurs.
[UserAgent] Tune based on expected application or script-based mailbox access.
[GeoLocation] Restrict based on corporate geography or travel expectations.

Detected Techniques

1

Details

MITRE ID
DET0393
STIX ID
x-mitre-detection-strategy--210a0dee-7c4b-4948-80ed-67c3e04886c2
Analytics
3
Techniques Detected
1
By Tactic
Privilege Escalation
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.