MITRE ATT&CK technique
Compromise Accounts detection rulesT1586
Compromise Accounts (T1586) is a MITRE ATT&CK technique in the Resource Development tactic. This page lists the 3 community-maintained Sigma detection rules in the library mapped to T1586 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target bitbucket, okta.
T1586 on attack.mitre.org3 rules
Top products
Tactic
Bitbucket Unauthorized Access To A Resource
criticalDetects unauthorized access attempts to a resource.
bitbucket
Bitbucket Unauthorized Full Data Export Triggered
criticalDetects when full data export is attempted an unauthorized user.
bitbucket
Okta Suspicious Activity Reported by End-user
highDetects when an Okta end-user reports activity by their account as being potentially suspicious.
okta