Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0488 — Detect abuse of Trusted Relationships (third-party and delegated admin access)
DET0488

Detect abuse of Trusted Relationships (third-party and delegated admin access)

7 analytic(s) · 1 technique(s) detected

Analytics

7
AN1344 Analytic 1344
Windows

Behavioral chain: (1) a login from a third-party account or untrusted source network establishes an interactive/remote session; (2) the session acquires elevated privileges or accesses sensitive resources atypical for that account; (3) subsequent lateral movement or data access occurs from the same session/device. Correlate Windows logon events, token elevation/privileged use, and resource access with third-party context.

WinEventLog:Security EventCode=4624, 4648 WinEventLog:Security EventCode=4776, 4771, 4770 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Security EventCode=4663, 4670, 4656
[ThirdPartyCIDRs] Ranges used by MSPs/contractors/VPN egress; used to enrich logons and network flows.
[ExpectedAdminHosts] Servers where third-party admins are allowed; deviations raise risk.
[TimeWindow] Correlation window linking logon → elevation → access (e.g., 30–120 minutes).
[HighValueResources] File shares/AD objects/servers that should never be touched by third-party sessions.
AN1345 Analytic 1345
Linux

Behavioral chain: (1) sshd or federated SSO logins from third-party networks or identities; (2) rapid sudo/su privilege elevation; (3) access to sensitive paths or east-west SSH. Correlate auth logs, process execution, and network flows.

auditd:SYSCALL execve,socket,connect,openat linux:syslog Accepted publickey/password for * from * port * ssh2 NSM:Flow ssh connections originating from third-party CIDRs
[ThirdPartyUsers] POSIX accounts assigned to vendors/partners.
[AllowedJumpHosts] Bastion hosts permitted for third-party access.
[MFAExpected] Flag indicating whether PAM/MFA should be present; used to score risk.
AN1346 Analytic 1346
macOS

Behavioral chain: (1) third-party interactive login or mobileconfig-based device enrollment; (2) privilege use or admin group change; (3) lateral movement mounts/ssh. Correlate unified logs and network telemetry.

macos:unifiedlog loginwindow or sshd successful login events macos:unifiedlog Group membership change for admin or wheel NSM:Flow ssh/smb connections to internal resources from third-party devices
[ManagedDeviceList] Known corp devices; treat unknown devices as higher risk.
AN1347 Analytic 1347
Identity Provider

Behavioral chain: (1) delegated admin or external identity establishes session (e.g., partner/reseller DAP, B2B guest, SAML/OAuth trust); (2) role elevation or app consent/permission grant; (3) downstream privileged actions in the tenant. Correlate IdP sign-in, admin/role assignment, and consent/admin-on-behalf events.

azure:signinlogs InteractiveUser, ServicePrincipalSignIn azure:audit Add delegated admin / Assign admin roles / Update application consent m365:unified Set-PartnerOfRecord / CompanyAdministrator role assignments / New-DelegatedAdminRelationship
[TrustedPartnerTenantIDs] Tenant IDs of approved partners; any others are suspicious.
[RequiredMFA] Require MFA for partner sessions; alert on bypass or step-up failure.
[RoleScopeAllowList] Roles third-parties may hold (e.g., Helpdesk Admin); flag broader scopes.
AN1348 Analytic 1348
IaaS

Behavioral chain: (1) cross-account or third-party principal assumes a role into the tenant/subscription/project; (2) privileged API calls are made in short succession; (3) access originates from unfamiliar networks or geos. Correlate assume-role/federation events with sensitive API usage.

AWS:CloudTrail AssumeRole,AssumeRoleWithSAML,AssumeRoleWithWebIdentity AWS:CloudTrail CreateUser|AttachRolePolicy|CreateAccessKey|UpdateAssumeRolePolicy|CreateLoginProfile gcp:audit google.iam.credentials.generateAccessToken / serviceAccountTokenCreator
[ExternalAccountAllowList] Cross-account principals permitted to assume roles; used for allow-listing.
[SensitiveAPIs] Provider-specific list of risky APIs for scoring.
[GeoVelocityThreshold] Detect impossible travel between partner and tenant actions.
AN1349 Analytic 1349
SaaS

Behavioral chain: (1) third-party app or admin connects via OAuth/marketplace install; (2) high-privilege scopes granted; (3) anomalous actions (mass read/exports, admin changes).

saas:googleworkspace OAuth2 authorization grants / Admin role assignments saas:salesforce ConnectedApp OAuth policy change / Login as user
[ApprovedApps] Catalog of sanctioned third-party apps and scopes.
[ExportVolumeThreshold] Data export size/rate baselines to detect abnormal partner activity.
AN1350 Analytic 1350
Office Suite

Behavioral chain: (1) delegated administration offers/relationships created or modified by partner tenants; (2) mailbox delegation/impersonation enabled; (3) follow-on access from partner IPs.

m365:unified Add-DelegatedAdmin, Set-PartnerOfRecord, Add-MailboxPermission, Set-OrganizationRelationship azure:signinlogs InteractiveUser, NonInteractiveUser
[MailboxDelegateAllowList] Specific mailboxes third-parties may manage.

Detected Techniques

1

Initial Access (1)

Details

MITRE ID
DET0488
STIX ID
x-mitre-detection-strategy--2f7a5ebd-e025-4822-aed2-46fc3ec1a0a9
Analytics
7
Techniques Detected
1
By Tactic
Initial Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.