Use Case: Account Manipulation
December 5, 2023 · View on GitHub
Use Case: Account Manipulation
Vendor: Absolute
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Absolute DDS | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: Accellion
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Kiteworks | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Airlock
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Airlock Allowlisting | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Amazon
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| AWS CloudTrail | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| AWS WAF | T1098 - Account Manipulation |
|
| Amazon EKS | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Amazon RDS | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: Apache
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Apache Subversion | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Atlassian
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Atlassian BitBucket | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Auth0
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Auth0 | T1098 - Account Manipulation T1136 - Create Account T1531 - Account Access Removal |
|
Vendor: BeyondTrust
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| BeyondInsight | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| BeyondTrust | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| BeyondTrust Privileged Identity | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| BeyondTrust Secure Remote Access | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Check Point
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Check Point NGFW | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
| Check Point Security Gateway | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
Vendor: Cisco
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| AnyConnect | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
| Cisco | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Cisco ACS | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Cisco Adaptive Security Appliance | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1484 - Group Policy Modification T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Cisco Firepower | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1484 - Group Policy Modification T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Cisco IOS | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Cisco ISE | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Cisco Unified Communications Manager | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Duo Access | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 T1531 - Account Access Removal |
|
Vendor: Citrix
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Citrix Gateway | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1484 - Group Policy Modification T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Citrix ShareFile | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Click Studios
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Passwordstate | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Cloudflare
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Cloudflare Insights | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account |
|
Vendor: Code42
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Code42 Incydr | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Cohesity
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Cohesity DataPlatform | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: CrowdStrike
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Falcon | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: CyberArk
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| CyberArk Privilege Access Manager | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Delinea
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Centrify Infrastructure Services | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Centrify Zero Trust Privilege Services | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Dell
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Sonicwall | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
Vendor: Digital Guardian
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Digital Guardian Endpoint Protection | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: Dropbox
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Dropbox | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
Vendor: Dtex Systems
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| DTEX InTERCEPT | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: ESET
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| ESET Endpoint Security | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Epic
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Epic SIEM | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Exabeam
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Audit Log | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Search | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Extreme Networks
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Zebra WLAN Management | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: F5
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| F5 Access Policy Manager | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
| F5 Advanced Web Application Firewall | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| F5 BIG-IP | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
| F5 BIG-IP DNS | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: FTP
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| FTP | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Fortinet
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| FortiGate | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
| Fortinet UTM | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: GitHub
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| GitHub | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Google
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Google Cloud Platform | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Google Workspace | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: HP
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Aruba Mobility Master | T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 |
|
| HPE Comware | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: HashiCorp
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| HashiCorp Vault | T1098 - Account Manipulation |
|
Vendor: HelpSystems
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Powertech Identity and Access Manager | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: Huawei
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Huawei Unified Security Gateway | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: IBM
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| IBM Mainframe | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| IBM Resource Access Control Facility | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Infoblox
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| BloxOne DDI | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: Ipswitch
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| MoveIt Transfer | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account |
|
Vendor: Ivanti
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Ivanti Pulse Secure | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1484 - Group Policy Modification T1531 - Account Access Removal |
|
Vendor: Juniper Networks
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Junos OS | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: Kemp
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Kemp LoadMaster | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: LanScope
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| LanScope Cat | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: LastPass
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| LastPass | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 |
|
Vendor: LogRhythm
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| LogRhythm | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: ManageEngine
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| ADSSP | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| PAM360 | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: McAfee
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Skyhigh Networks CASB | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Microsoft
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Azure | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Azure AD Activity Logs | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Azure MFA | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Azure Monitor | T1078.004 - Valid Accounts: Cloud Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136.003 - Create Account: Create: Cloud Account |
|
| Azure Monitor - VM Insights | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Event Viewer - ADFS | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Event Viewer - AzureADPasswordProtection-DCAgent | T1098 - Account Manipulation |
|
| Event Viewer - DHCP-Server | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Event Viewer - DNSServer | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Event Viewer - PowerShell | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Event Viewer - Security | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 T1207 - Rogue Domain Controller T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1484 - Group Policy Modification T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Event Viewer - System | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Event Viewer - TaskScheduler | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Event Viewer - TerminalServices-Gateway | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Event Viewer - TerminalServices-LocalSessionManager | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| M365 Audit Logs | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Microsoft 365 | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Microsoft CAS | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Microsoft Defender for Endpoint | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Microsoft Exchange | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Microsoft Intune | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Microsoft WMI Log | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Sysmon | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: Mimecast
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Mimecast Secure Email Gateway | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: NCP
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| NCP | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
Vendor: Namespace rDirectory
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Namespace rDirectory | T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 T1207 - Rogue Domain Controller T1484 - Group Policy Modification T1531 - Account Access Removal |
|
Vendor: Netskope
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Netskope Security Cloud | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Netwrix
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Netwrix Auditor | T1098 - Account Manipulation |
|
Vendor: NextDLP
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Reveal | T1098 - Account Manipulation T1136 - Create Account |
|
Vendor: Nortel Contivity
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Nortel Contivity VPN | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
Vendor: Okta
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Okta Adaptive MFA | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 |
|
Vendor: OneLogin
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| OneLogin | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: OneWelcome
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| OneWelcome Cloud Identity Platform | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: Open VPN
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Open VPN | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
Vendor: Oracle
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Oracle Public Cloud | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 |
|
Vendor: Osquery
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Osquery | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Palo Alto Networks
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| GlobalProtect | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
| Palo Alto NGFW | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
Vendor: Password Manager Pro
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Password Manager Pro | T1098 - Account Manipulation T1136 - Create Account T1531 - Account Access Removal |
|
Vendor: Ping Identity
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Ping Identity | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Proofpoint
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| ObserveIT | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: Quest Software
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Quest Change Auditor for Active Directory | T1098 - Account Manipulation T1136 - Create Account T1207 - Rogue Domain Controller T1484 - Group Policy Modification |
|
Vendor: RSA
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| SecurID | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
Vendor: Rubrik
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Rubrik Cloud Data Management | T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 |
|
Vendor: SAP
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| SAP | T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 T1531 - Account Access Removal |
|
Vendor: Sailpoint
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| IdentityNow | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Salesforce
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Salesforce | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: SecureAuth
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| SecureAuth IDP | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: SecureNet
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| SecureNet | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification |
|
Vendor: Semperis
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Semperis DSP | T1207 - Rogue Domain Controller T1484 - Group Policy Modification |
|
Vendor: SentinelOne
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Singularity Platform | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Vigilance | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 |
|
Vendor: ServiceNow
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| ServiceNow | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Shibboleth
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Shibboleth | T1098 - Account Manipulation |
|
Vendor: SkySea
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| SkySea ClientView | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: Specops
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Specops Password | T1098 - Account Manipulation |
|
Vendor: SunOne
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| SunOne | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Symantec
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Symantec Advanced Threat Protection | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Symantec Critical System Protection | T1098 - Account Manipulation T1136 - Create Account |
|
Vendor: Tanium
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Tanium Cloud Platform | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Tanium Core Platform | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Tanium Integrity Monitor | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
Vendor: Trend Micro
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Deep Discovery Inspector | T1098 - Account Manipulation |
|
Vendor: Unix
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Auditbeat | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Unix | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Unix Auditd | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Unix dhcpd | T1098 - Account Manipulation |
|
Vendor: VMware
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Carbon Black App Control | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Carbon Black CES | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| Carbon Black EDR | T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002 |
|
| VMware AirWatch | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| VMware ESXi | T1098 - Account Manipulation |
|
| VMware Horizon | T1098 - Account Manipulation |
|
Vendor: Vectra
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Vectra Cognito Detect | T1098 - Account Manipulation |
|
Vendor: Wiz
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Wiz | T1136 - Create Account T1531 - Account Access Removal |
|
Vendor: Zeek
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Zeek | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: Zendesk
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Zendesk | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor:
Vendor: iManage
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| iManage | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
Vendor: oVirt
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| oVirt | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|