MITRE ATT&CK technique
Account Manipulation detection rulesT1098
Account Manipulation (T1098) is a MITRE ATT&CK technique in the Persistence tactic. This page lists the 44 community-maintained Sigma detection rules in the library mapped to T1098 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, azure, aws.
Active Directory User Backdoors
highDetects scenarios where one can control another users or computers account without having to use their credentials.
windows
Added Credentials to Existing Application
highDetects when a new credential is added to an existing application. Any additional credentials added outside of expected processes could be a malicious actor using those credentials.
azure
Anomalous User Activity
highIndicates that there are anomalous patterns of behavior like suspicious changes to the directory.
azure
App Granted Privileged Delegated Or App Permissions
highDetects when administrator grants either application permissions (app roles) or highly privileged delegated permissions
azure
AWS User Login Profile Was Modified
highDetects activity when someone is changing passwords on behalf of other users. An attacker with the "iam:UpdateLoginProfile" permission on other users can change the password used to login to the AWS console on any user that already has a login profile setup.
aws
Bulk Deletion Changes To Privileged Account Permissions
highDetects when a user is removed from a privileged role. Bulk changes should be investigated.
azure
Cisco Local Accounts
highFind local accounts being created or modified as well as remote authentication configurations
cisco
Enabled User Right in AD to Control User Objects
highDetects scenario where if a user is assigned the SeEnableDelegationPrivilege right in Active Directory it would allow control of other AD user objects.
windows
ESXi Admin Permission Assigned To Account Via ESXCLI
highDetects execution of the "esxcli" command with the "system" and "permission" flags in order to assign admin permissions to an account.
linux · process_creation
Password Change on Directory Service Restore Mode (DSRM) Account
highDetects potential attempts made to set the Directory Services Restore Mode administrator password. The Directory Service Restore Mode (DSRM) account is a local administrator account on Domain Controllers. Attackers may change the password in order to obtain persistence.
windows
Powerview Add-DomainObjectAcl DCSync AD Extend Right
highBackdooring domain object to grant the rights associated with DCSync to a regular user or machine account using Powerview\Add-DomainObjectAcl DCSync Extended Right cmdlet, will allow to re-obtain the pwd hashes of any user/computer
windows
Privileged User Has Been Created
highDetects the addition of a new user to a privileged group such as "root" or "sudo"
linux
Suspicious Computer Account Name Change CVE-2021-42287
highDetects the renaming of an existing computer account to a account name that doesn't contain a $ symbol as seen in attacks against CVE-2021-42287
windows
User Added To Highly Privileged Group
highDetects addition of users to highly privileged groups via "Net" or "Add-LocalGroupMember".
windows · process_creation
Windows LAPS Credential Dump From Entra ID
highDetects when an account dumps the LAPS password from Entra ID.
azure
A New Trust Was Created To A Domain
mediumAddition of domains is seldom and should be verified for legitimacy.
windows
App Assigned To Azure RBAC/Microsoft Entra Role
mediumDetects when an app is assigned Azure AD roles, such as global administrator, or Azure RBAC roles, such as subscription owner.
azure
AWS IAM Backdoor Users Keys
mediumDetects AWS API key creation for a user by another user. Backdoored users can be used to obtain persistence in the AWS environment. Also with this alert, you can detect a flow of AWS keys in your org.
aws
Bitbucket Global Permission Changed
mediumDetects global permissions change activity.
bitbucket
Change to Authentication Method
mediumChange to authentication method could be an indicator of an attacker adding an auth method to the account so they can have continued access.
azure
DMSA Service Account Created in Specific OUs - PowerShell
mediumDetects the creation of a dMSA service account using the New-ADServiceAccount cmdlet in certain OUs. The fact that the cmdlet is used to create a dMSASvc account in a specific OU is highly suspicious. It is a pattern trying to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025. On top of that, if the user that is creating the dMSASvc account is not a legitimate administrator or does not have the necessary permissions, it is a strong signal of an attempted or successful abuse of the BaDSuccessor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.
windows · ps_script
GCP Access Policy Deleted
mediumDetects when an access policy that is applied to a GCP cloud resource is deleted. An adversary would be able to remove access policies to gain access to a GCP cloud resource.
gcp
Github Outside Collaborator Detected
mediumDetects when an organization member or an outside collaborator is added to or removed from a project board or has their permission level changed or when an owner removes an outside collaborator from an organization or when two-factor authentication is required in an organization and an outside collaborator does not use 2FA or disables 2FA.
github
Google Workspace Application Access Level Modified
mediumDetects when an access level is changed for a Google workspace application. An access level is part of BeyondCorp Enterprise which is Google Workspace's way of enforcing Zero Trust model. An adversary would be able to remove access levels to gain easier access to Google workspace resources.
gcp
Google Workspace Granted Domain API Access
mediumDetects when an API access service account is granted domain authority.
gcp
Google Workspace User Granted Admin Privileges
mediumDetects when an Google Workspace user is granted admin privileges.
gcp
Granting Of Permissions To An Account
mediumIdentifies IPs from which users grant access to other users on azure resources and alerts when a previously unseen source IP address is used.
azure
msDS-ManagedAccountPrecededByLink Attribute Modified
mediumDetects modifications to the msDS-ManagedAccountPrecededByLink attribute, which may indicate an attempted or successful abuse of the BaD-Successor msDS-DelegatedManagedServiceAccount (DMSA) vulnerability. The DMSA is a new object class introduced in Windows Server 2025 that allows administrators to delegate the management of service accounts to other users or groups. Changes to this attribute by suspicious accounts or outside of normal administrative workflows are a strong signal of an attempted or successful abuse. If it is indeed modified by an account that is not typically responsible for such changes, it could indicate an attempt to exploit the BaD-Successor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.
windows
New DMSA Service Account Created in Specific OUs
mediumDetects the creation of a dMSASvc account using the New-ADServiceAccount cmdlet in certain OUs. The fact that the Cmdlet is used to create a dMSASvc account in a specific OU is highly suspicious. It is a pattern trying to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025. On top of that, if the user that is creating the dMSASvc account is not a legitimate administrator or does not have the necessary permissions, it is a strong signal of an attempted or successful abuse of the BaDSuccessor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.
windows · process_creation
New MsDS-DelegatedManagedServiceAccount (DMSA) Object Created
mediumDetects the creation of new msDS-DelegatedManagedServiceAccount objects, which could indicate potential abuse of privilege escalation vulnerabilities in Windows Server 2025. The msDS-DelegatedManagedServiceAccount (DMSA) is a new object class introduced in Windows Server 2025 that allows administrators to delegate the management of service accounts to other users or groups. Attackers may exploit this feature to create unauthorized service accounts with elevated privileges, leading to privilege escalation within the Active Directory environment. It is highly suspicious if an msDS-DelegatedManagedServiceAccount object is created without proper authorization or in an unexpected context, such as by a non-administrative user or outside of normal administrative workflows. So, it's a good idea to look out for accounts that are not typically responsible for service account creation to detect potential abuse of this feature.
windows
Number Of Resource Creation Or Deployment Activities
mediumNumber of VM creations or deployment activities occur in Azure via the azureactivity log.
azure
Okta Admin Role Assigned to an User or Group
mediumDetects when an the Administrator role is assigned to an user or group.
okta
Okta Identity Provider Created
mediumDetects when a new identity provider is created for Okta.
okta
Password Set to Never Expire via WMI
mediumDetects the use of wmic.exe to modify user account settings and explicitly disable password expiration.
windows · process_creation
Powershell LocalAccount Manipulation
mediumAdversaries may manipulate accounts to maintain access to victim systems. Account manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups
windows · ps_script
User Added to an Administrator's Azure AD Role
mediumUser Added to an Administrator's Azure AD Role
azure
User Added to Local Administrator Group
mediumDetects the addition of a new member to the local administrator group, which could be legitimate activity or a sign of privilege escalation activity
windows
User Added to Local Administrators Group
mediumDetects addition of users to the local administrator group via "Net" or "Add-LocalGroupMember".
windows · process_creation
A Member Was Added to a Security-Enabled Global Group
lowDetects activity when a member is added to a security-enabled global group
windows
A Member Was Removed From a Security-Enabled Global Group
lowDetects activity when a member is removed from a security-enabled global group
windows
A Security-Enabled Global Group Was Deleted
lowDetects activity when a security-enabled global group is deleted
windows
AWS Route 53 Domain Transfer Lock Disabled
lowDetects when a transfer lock was removed from a Route 53 domain. It is recommended to refrain from performing this action unless intending to transfer the domain to a different registrar.
aws
AWS Route 53 Domain Transferred to Another Account
lowDetects when a request has been made to transfer a Route 53 domain to another AWS account.
aws
DMSA Link Attributes Modified
lowDetects modification of dMSA link attributes (msDS-ManagedAccountPrecededByLink) via PowerShell scripts. This command line pattern could be an indicator an attempt to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025.
windows · ps_script