Account Manipulation: Additional Cloud Credentials T1098.001
Tactics: Persistence, Privilege Escalation
Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.
Authoring guide
Patterns shared across the 56 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (77 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (161 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (8 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 8 rules
- Added Credentials to Existing Application
- API Key Created
- Attempt To Create API Key
- Github Outside Collaborator Detected
- IAM Access Key Created
- IAM Access Key Creation Attempt
- IAM Login Profile Created
- Okta Identity Provider Created
Elastic 23 rules
- Application Added to Google Workspace Domain
- Attempt to Create Okta API Token
- AWS EC2 Instance Interaction with IAM Service
- AWS First Occurrence of STS GetFederationToken Request by User
- AWS IAM Login Profile Added for Root
- AWS IAM Login Profile Added to User
- AWS IAM SAML Provider Created
- AWS IAM User Created Access Keys For Another User
- AWS RDS DB Instance or Cluster Password Modified
- AWS Sensitive IAM Operations Performed via CloudShell
- Azure Storage Account Key Regenerated
- Entra ID Application Credential Modified
- Entra ID Domain Federation Configuration Change
- Entra ID Federated Identity Credential Issuer Modified
- Entra ID Service Principal Credentials Created by Unusual User
- Entra ID Service Principal Federated Credential Authentication by Unusual Client
- Entra ID Sharepoint or OneDrive Accessed by Unusual Client
- First Occurrence GitHub Event for a Personal Access Token (PAT)
- First Occurrence of Personal Access Token (PAT) Use For a GitHub User
- GCP Service Account Key Creation
- Google Workspace Object Copied to External Drive with App Consent
- New GitHub Personal Access Token (PAT) Added
- New User Added To GitHub Organization
Splunk 2 rules
Kusto 5 rules
- AWS Security Hub - Detect IAM root user Access Key existence
- AWSCloudTrail - Changes to internet facing AWS RDS Database instances
- AWSCloudTrail - Creation of Access Key for IAM User
- Detect credential add to Connect Sync Application
- New External User Granted Admin Role
YARA-L 6 rules
- Client Secret Added to Entra ID Application
- GitHub Personal Access Token Created from Tor IP Address
- GitHub Repository Deploy Key Created Or Modified
- Google Cloud Service Account Key Created or Uploaded
- O365 AD PowerShell App Login Subsequent Activity
- O365 Entra ID App Client Secret Added, Updated or Deleted
Panther 12 rules
- A Teleport Role was modified or created
- Anthropic Admin API Key Created
- Anthropic Admin API Key Deleted
- Anthropic Service Key Created
- Anthropic Service Key Revoked
- AWS Privilege Escalation Via User Compromise
- AWS User Takeover Via Password Reset
- Azure Service Principal Credentials Added
- Crowdstrike API Key Created
- Crowdstrike User Password Changed
- IAM Role Added to RDS Instance or Cluster
- Wiz User Role Updated Or Deleted