Account Manipulation T1098

Tactics: Persistence, Privilege Escalation

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

Events covered

51 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 13RegistryEvent (Value Set)
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4625An account failed to log on.
Security-AuditingEvent ID 4634An account was logged off.
Security-AuditingEvent ID 4662An operation was performed on an object.
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4673A privileged service was called.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4704A user right was assigned.
Security-AuditingEvent ID 4706A new trust was created to a domain.
Security-AuditingEvent ID 4720A user account was created.
Security-AuditingEvent ID 4722A user account was enabled.
Security-AuditingEvent ID 4723An attempt was made to change an account's password.
Security-AuditingEvent ID 4724An attempt was made to reset an account's password.
Security-AuditingEvent ID 4725A user account was disabled.
Security-AuditingEvent ID 4726A user account was deleted.
Security-AuditingEvent ID 4727A security-enabled global group was created.
Security-AuditingEvent ID 4728A member was added to a security-enabled global group.
Security-AuditingEvent ID 4729A member was removed from a security-enabled global group.
Security-AuditingEvent ID 4730A security-enabled global group was deleted.
Security-AuditingEvent ID 4731A security-enabled local group was created.
Security-AuditingEvent ID 4732A member was added to a security-enabled local group.
Security-AuditingEvent ID 4733A member was removed from a security-enabled local group.
Security-AuditingEvent ID 4738A user account was changed.
Security-AuditingEvent ID 4741A computer account was created.
Security-AuditingEvent ID 4742A computer account was changed.
Security-AuditingEvent ID 4754A security-enabled universal group was created.
Security-AuditingEvent ID 4756A member was added to a security-enabled universal group.
Security-AuditingEvent ID 4757A member was removed from a security-enabled universal group.
Security-AuditingEvent ID 4781The name of an account was changed.
Security-AuditingEvent ID 4794An attempt was made to set the Directory Services Restore Mode administrator password.
Security-AuditingEvent ID 5136A directory service object was modified.
Security-AuditingEvent ID 5137A directory service object was created.
Security-AuditingEvent ID 5145A network share object was checked to see whether client can be granted desired access.
1Password-GroupMembershipgm-joinJoin Group
1Password-GroupVaultAccessanyGroup vault access (catch-all)
1Password-UserVaultAccessanyUser vault access (catch-all)
Defender-DeviceEventsUserAccountAddedToLocalGroupUser account added to local group
Defender-DeviceEventsUserAccountCreatedUser account created
Defender-DeviceEventsUserAccountModifiedUser account modified
Defender-DeviceProcessEventsanyProcess activity
Defender-IdentityInfoanyIdentity information
Linux-AuditdEvent ID 1302PATH
Linux-AuditdEvent ID 1307CWD
MSSQLSERVEREvent ID 33205Event ID 33205
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
PowerShellEvent ID 800Event ID 800
Sysmon-for-LinuxEvent ID 1Process Create
Sysmon-for-LinuxEvent ID 11File created

Authoring guide

These 587 rules share fields, values, and exclusions.

Fields filtered most (464 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
data_stream.dataset117eq 117aws.cloudtrail, azure.auditlogs, gcp.audit, google_workspace.admin, o365.audit
EventType115eq 72, in 37, wildcard 4, is_not_null 1, starts_with 1exec, ProcessRollup2, exec_event, io.k8s.certificates.v1.certificatesigningrequests.create, createaccesskey
event.outcome81eq 81success, failure
aws::eventName59in 31, eq 28AttachGroupPolicy, AttachRolePolicy, AttachUserPolicy, PutGroupPolicy, PutRolePolicy
EventID58eq 49, in 8, regex_match 34728, 5136, 4732, 4720, 4738
Provider_Name48eq 46, in 2iam.amazonaws.com, bedrock.amazonaws.com, exchange, eks.amazonaws.com, microsoft entra id
sourcetype41eq 39, in 2o365:management:activity, azure:monitor:aad, aws:asl, aws:cloudtrail, vmw-syslog
aws::errorCode39is_null 29, eq 5, in 3, is_not_null 2accessdenied, accessdeniedexception, deleteconflictexception, nosuchentityexception, success
Action26contains 22, eq 4CREATE, kms:delete, cloudformation:*, cloudformation:create*, cloudformation:createstack
aws::errorMessage26is_null 26
type25eq 21, in 4, starts_with 1user, serviceprincipal, API_KEY, OAUTH_CLIENT, AUTH_KEY
OperationName24eq 17, in 5, contains 2add app role assignment to service principal, add member to role, set domain authentication, set federation settings on domain, Library.ServiceConnectionExecuted
host.os.type24eq 24
Condition22eq 20, is_null 2
Effect22eq 22allow

Top indicator values (2227 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
79369
data_stream.dataseteq
aws.cloudtrail
33169
data_stream.dataseteq
azure.auditlogs
1726
data_stream.dataseteq
gcp.audit
1669
data_stream.dataseteq
google_workspace.admin
918
data_stream.dataseteq
o365.audit
947
data_stream.dataseteq
azure.signinlogs
736
Effecteq
allow
2226
Provider_Nameeq
iam.amazonaws.com
2232
Resourceeq
*
2223
sourcetypeeq
o365:management:activity
1680
sourcetypeeq
azure:monitor:aad
1547
aws::eventNamein
AttachGroupPolicy
1417
aws::eventNamein
AttachRolePolicy
1417
aws::eventNamein
AttachUserPolicy
1417
aws::eventNamein
CreatePolicy
1114
aws::eventNamein
CreatePolicyVersion
1114
aws::eventNamein
PutGroupPolicy
1112
aws::eventNamein
PutRolePolicy
1112
aws::eventNamein
PutUserPolicy
1112
security_result.actioneq
ALLOW
13102
aws::eventSourceeq
iam.amazonaws.com
1228
ServiceNameeq
k8s.io
1137
Actioncontains
iam:*
1010
Actioncontains
iam:passrole
1010
Workloadeq
azureactivedirectory
930
kubernetes.audit.annotations.authorization_k8s_io/decisioneq
allow
925
metadata.log_typeeq
SAP_CHANGE_DOCUMENT
88
Categoryeq
rolemanagement
721
OperationTypeeq
%%14674
717

Exclusions (255 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
aws::userIdentity.typeeq
awsservice
5
AllowedToDelegateToeq
-
4
SubjectUserSideq
s-1-5-18
4
aws::sourceIPAddressin
cloudformation.amazonaws.com
4
aws::sourceIPAddressin
servicecatalog.amazonaws.com
4
aws::userAgentcontains
ansible
4
aws::userAgentcontains
pulumi
4
aws::userAgentcontains
terraform
4
aws::userIdentity.arncontains
terraform
4
responseStatus.codege
1
4
responseStatus.codege
400
4
responseStatus.codele
16
4
source.as.organization.namestarts_with
AMAZON
4
source.as.organization.namestarts_with
Amazon
4
usernamein
aksService
4

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 100 rules

Elastic 174 rules

Splunk 70 rules

Kusto 131 rules

YARA-L 29 rules

Panther 83 rules