Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0546 — Detection of Abused or Compromised Cloud Accounts for Access and Persistence
DET0546

Detection of Abused or Compromised Cloud Accounts for Access and Persistence

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN1503 Analytic 1503
Identity Provider

Detects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts.

azure:signinlogs Sign-in activity saas:okta user.authentication.sso
[AnomalousLocationThreshold] Defines geographic separation (e.g., impossible travel) considered suspicious.
[ProtocolType] Filter based on legacy or deprecated authentication mechanisms.
AN1504 Analytic 1504
IaaS

Detects cloud account use for API calls that exceed normal scope, such as IAM changes or access to services never used before.

AWS:CloudTrail ConsoleLogin, AssumeRole, ListAccessKeys, CreateUser gcp:audit admin.googleapis.com
[ServiceInteractionBaseline] Custom list of expected service interactions per user or role.
[RoleSwitchRateThreshold] Frequency of assume-role operations that triggers an alert.
AN1505 Analytic 1505
SaaS

Detects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users.

m365:unified FileAccessed, SharingSet gcp:audit drive.activity
[FileDownloadThreshold] Defines excessive access based on number or size of downloads.
[SharingPolicyViolationThreshold] Defines external sharing behaviors that violate policy.
AN1506 Analytic 1506
Office Suite

Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles.

m365:signinlogs UserLogin gcp:audit login.event
[BusinessHours] Used to identify logins outside of expected work times.
[OfficeProductivityToolBaseline] Defines expected application usage per department or role.

Detected Techniques

1

Details

MITRE ID
DET0546
STIX ID
x-mitre-detection-strategy--a1a9e316-145a-4744-a594-7decc23c543d
Analytics
4
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.