Create Account: Cloud Account T1136.003
Tactic: Persistence
Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system.
Events covered
1 catalog event is tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
Authoring guide
Patterns shared across the 56 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (64 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (167 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (17 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 5 rules
- AWS ElastiCache Security Group Created
- IAM User Created
- IAM User Creation Attempt
- New Federated Domain Added - Exchange
- New Github Organization Member Added
Elastic 9 rules
- AWS IAM Create User via Assumed Role on EC2 Instance
- AWS IAM Group Creation
- AWS IAM Sensitive Operations via Lambda Execution Role
- AWS Sensitive IAM Operations Performed via CloudShell
- Entra ID External Guest User Invited
- Entra ID Service Principal Created
- GCP Service Account Creation
- New GitHub Owner Added
- New GitHub Personal Access Token (PAT) Added
Splunk 20 rules
- ASL AWS Create Access Key
- ASL AWS UpdateLoginProfile
- AWS CreateAccessKey
- AWS CreateLoginProfile
- AWS UpdateLoginProfile
- Azure AD External Guest User Invited
- Azure AD Multiple Service Principals Created by SP
- Azure AD Multiple Service Principals Created by User
- Azure AD Service Principal Created
- Azure Automation Account Created
- Azure Automation Runbook Created
- O365 Add App Role Assignment Grant User
- O365 Added Service Principal
- O365 External Guest User Invited
- O365 External Identity Policy Changed
- O365 Multiple Service Principals Created by SP
- O365 Multiple Service Principals Created by User
- O365 New Federated Domain Added
- O365 SharePoint Allowed Domains Policy Changed
- Windows Azure PowerShell Module Installation Via PowerShell Script
Kusto 11 rules
- Account created from non-approved sources
- Cross-tenant Access Settings Organization Added
- Cross-tenant Access Settings Organization Deleted
- Cross-tenant Access Settings Organization Inbound Collaboration Settings Changed
- Cross-tenant Access Settings Organization Inbound Direct Settings Changed
- Cross-tenant Access Settings Organization Outbound Collaboration Settings Changed
- Cross-tenant Access Settings Organization Outbound Direct Settings Changed
- External guest invitation followed by Microsoft Entra ID PowerShell signin
- Guest accounts added in Entra ID Groups other than the ones specified
- User Account Created Using Incorrect Naming Format
- User account created without expected attributes defined
YARA-L 3 rules
- AWS Privilege Escalation Using IAM Access Key
- AWS Privilege Escalation Using IAM Login Profile
- GCP Free Gmail Domains Added To IAM Policy