Valid Accounts T1078

Tactics: Stealth, Persistence, Privilege Escalation, Initial Access

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Events covered

56 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4625An account failed to log on.
Security-AuditingEvent ID 4634An account was logged off.
Security-AuditingEvent ID 4647User initiated logoff.
Security-AuditingEvent ID 4648A logon was attempted using explicit credentials.
Security-AuditingEvent ID 4662An operation was performed on an object.
Security-AuditingEvent ID 4675SIDs were filtered.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4720A user account was created.
Security-AuditingEvent ID 4722A user account was enabled.
Security-AuditingEvent ID 4723An attempt was made to change an account's password.
Security-AuditingEvent ID 4724An attempt was made to reset an account's password.
Security-AuditingEvent ID 4725A user account was disabled.
Security-AuditingEvent ID 4726A user account was deleted.
Security-AuditingEvent ID 4727A security-enabled global group was created.
Security-AuditingEvent ID 4728A member was added to a security-enabled global group.
Security-AuditingEvent ID 4729A member was removed from a security-enabled global group.
Security-AuditingEvent ID 4731A security-enabled local group was created.
Security-AuditingEvent ID 4732A member was added to a security-enabled local group.
Security-AuditingEvent ID 4733A member was removed from a security-enabled local group.
Security-AuditingEvent ID 4738A user account was changed.
Security-AuditingEvent ID 4742A computer account was changed.
Security-AuditingEvent ID 4754A security-enabled universal group was created.
Security-AuditingEvent ID 4756A member was added to a security-enabled universal group.
Security-AuditingEvent ID 4757A member was removed from a security-enabled universal group.
Security-AuditingEvent ID 4768A Kerberos authentication ticket (TGT) was requested.
Security-AuditingEvent ID 4769A Kerberos service ticket was requested.
Security-AuditingEvent ID 4776The domain controller attempted to validate the credentials for an account.
Security-AuditingEvent ID 4781The name of an account was changed.
Security-AuditingEvent ID 4964Special groups have been assigned to a new logon.
Security-AuditingEvent ID 5136A directory service object was modified.
Security-AuditingEvent ID 5137A directory service object was created.
Security-AuditingEvent ID 5138A directory service object was undeleted.
Security-AuditingEvent ID 5139A directory service object was moved.
Security-AuditingEvent ID 5141A directory service object was deleted.
1Password-GroupMembershipanyGroup membership (catch-all)
1Password-SignInAttemptcredentials_okcredentials_ok
1Password-SignInAttemptmfa_okmfa_ok
1Password-UserVaultAccessanyUser vault access (catch-all)
Defender-AlertEvidenceanyAlert evidence
Defender-AlertInfoanyAlert information
Defender-DeviceLogonEventsanyLogon activity
Defender-DeviceProcessEventsanyProcess activity
Defender-ExposureGraphEdgesanyExposure graph edges
Defender-IdentityInfoanyIdentity information
ESFexecProcess Execution
Linux-AuditdEvent ID 1100USER_AUTH
Linux-AuditdEvent ID 1105USER_START
Linux-AuditdEvent ID 1112USER_LOGIN
MSSQLSERVEREvent ID 18470Event ID 18470
MSSQLSERVEREvent ID 33205Event ID 33205
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
TerminalServices-RemoteConnectionManagerEvent ID 1149Remote Desktop Services: User authentication succeeded.
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 810 rules share fields, values, and exclusions.

Fields filtered most (795 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
data_stream.dataset116eq 111, in 5, ne 1azure.signinlogs, aws.cloudtrail, okta.system, azure.auditlogs, o365.audit
EventType105eq 86, in 17, starts_with 3, contains 1, wildcard 1login, access, sign-in activity, ssh_login, userloggedin
event.outcome80eq 80success, failure
EventID65eq 57, in 7, regex_match 15136, 4624, 1, 4104, 4688
OperationName48eq 24, contains 19, in 8update application, add member to role, add app role assignment to service principal, update a partner cross-tenant access setting, delete user
aws::eventName44eq 38, in 5, starts_with 1consolelogin, ConsoleLogin, updatesamlprovider, createaccesskey, getcredentialsforidentity
sourcetype37eq 33, in 4azure:monitor:aad, aws:cloudtrail, oktaim2:log, vmw-syslog, vmware:esxlog*
Category36eq 35, contains 1rolemanagement, applicationmanagement, usermanagement, ApplicationManagement, RoleManagement
Provider_Name34eq 33, in 1iam.amazonaws.com, signin.amazonaws.com, sts.amazonaws.com, azureactivedirectory, ec2.amazonaws.com
type31eq 27, in 6user, policy, role, serviceprincipal, User
displayName30eq 29, in 3, contains 1, is_not_null 1role.displayname, Role.DisplayName, role.wellknownobjectname, AppRole.Value, KeyDescription
src_ip30is_not_null 20, eq 7, ne 4, cidr_match 3, contains 1, cross_field_compare 1-, 10.0.0.0/8, 127.0.0.1, 127.0.0.0/8, %admin_jump_hosts%
event.category26eq 26authentication, configuration, process
ResultType24eq 19, in 3, ne 30, 50057, 50074, 500121, 50076
aws::userIdentity.type23eq 21, in 2, ne 2iamuser, AssumedRole, assumedrole, Root, FederatedUser

Top indicator values (2642 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
80369
data_stream.dataseteq
aws.cloudtrail
28169
data_stream.dataseteq
azure.signinlogs
2736
data_stream.dataseteq
okta.system
1348
data_stream.dataseteq
azure.auditlogs
826
data_stream.dataseteq
o365.audit
747
Categoryeq
rolemanagement
1821
Categoryeq
applicationmanagement
713
event.categoryeq
authentication
1834
event.categoryeq
configuration
713
Resulteq
success
1631
security_result.actioneq
ALLOW
15102
ResultTypeeq
0
1221
typeeq
user
1216
Provider_Nameeq
iam.amazonaws.com
932
Provider_Nameeq
signin.amazonaws.com
78
azure_ad::user_typeeq
member
911
EventIDeq
5136
845
RoleNamecontains
admin
89
aws::eventSourceeq
iam.amazonaws.com
828
event.dataseteq
aws.cloudtrail
817
event.dataseteq
github.audit
714
EventTypeeq
login
78
aws::errorCodeeq
accessdenied
716
aws::eventNameeq
consolelogin
719
azure_ad::activity_display_namecontains
add eligible member to role
710
azure_ad::activity_display_namecontains
add member to role
710
enough_dataeq
1
710
All_Changes.actioneq
created
611
All_Changes.statuseq
success
66

Exclusions (724 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
responseStatus.codege
1
6
responseStatus.codege
400
6
responseStatus.codele
16
6
usernamein
aksService
6
usernamein
masterclient
6
usernamestarts_with
system:
6
verbne
create
5
SubjectUserNameends_with
$
4
resultSignaturene
SUCCESS
4
src_ipcidr_match
10.0.0.0/8
4
src_ipcidr_match
127.0.0.0/8
4
src_ipcidr_match
169.254.0.0/16
4
src_ipcidr_match
172.16.0.0/12
4
src_ipcidr_match
192.168.0.0/16
4
Resulteq
success
3

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 118 rules

Elastic 210 rules

Splunk 81 rules

Kusto 274 rules

YARA-L 29 rules

Panther 98 rules