Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0277 — Detection Strategy for Role Addition to Cloud Accounts
DET0277

Detection Strategy for Role Addition to Cloud Accounts

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN0771 Analytic 0771
IaaS

Detection of new IAM roles or policies attached to a user/service in AWS/GCP/Azure outside normal patterns or hours, often following account compromise.

AWS:CloudTrail AttachUserPolicy, CreatePolicyVersion, PutRolePolicy
[RoleScope] IAM Role type or privilege level assigned (e.g., Admin, Billing, Viewer)
[UserContext] User, service account, or external federated identity context performing the action
[PolicyChangeTimeWindow] How quickly multiple roles or policies are added after initial access
[ExternalRoleOrigin] Cross-account roles from outside trusted tenant list
AN0772 Analytic 0772
Identity Provider

Behavioral chain of a user being granted elevated privileges or roles in Entra ID or Okta following suspicious login or account creation activity.

m365:audit Add member to role, Add app role assignment
[AdminRoleThreshold] Number of accounts allowed to hold sensitive roles like Global Admin
[RoleAssignmentMethod] Mechanism by which role was added (PowerShell, API, UI)
[GrantContext] Expected user-to-role mapping defined by org policy
AN0773 Analytic 0773
Office Suite

Detection of new admin or role assignment actions within Microsoft 365/O365 environments to elevate access for persistence or lateral movement.

m365:unified Add member to role, Set-Mailbox
[OfficeRoleType] Admin role type or application role granted
[TimeWindow] Time between initial login and privilege change
[ActionOrigin] Was the role assignment local or via federated SSO account

Detected Techniques

1

Details

MITRE ID
DET0277
STIX ID
x-mitre-detection-strategy--264a9ce0-b26f-4cc6-bdf4-384b0d188a95
Analytics
3
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.