Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1078.004

T1078.004Cloud Accounts

T1078.004 — Cloud Accounts is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 69 detection use cases covering it and 18 threat-intel articles citing it.

Defense EvasionPersistencePrivilege EscalationInitial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
69Use cases
18Articles
0Sub-techniques
4Tactics

Use cases covering this technique (69)

Abnormal Security: login from new location Internal delivery · alerting DD Auth0 impossible-travel sign-in Internal delivery · alerting DD Impossible travel observed for IAM user Internal delivery · alerting DDCW AWS root account activity (any action) Internal delivery · alerting DDCW Azure AD brute-force login Internal delivery · alerting DD Datadog suspicious login Internal delivery · alerting DD GitHub PAT used from impossible-travel locations Internal delivery · alerting DD Google Workspace service account modifying group membership Internal install · alerting DD [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Internal exploit · alerting DSPDDCW [WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Internal actions · alerting DSPDD Okta Authentication Failed During MFA Challenge ESCU actions · alerting P Okta Successful Single Factor Authentication ESCU actions · hunting P Okta ThreatInsight Threat Detected ESCU actions · hunting P ASL AWS Create Policy Version to allow all resources ESCU actions · alerting P AWS Create Policy Version to allow all resources ESCU actions · alerting P AWS SetDefaultPolicyVersion ESCU actions · alerting P AWS Successful Single-Factor Authentication ESCU actions · alerting P Azure AD Authentication Failed During MFA Challenge ESCU actions · alerting P Azure AD Multiple Failed MFA Requests For User ESCU actions · alerting P Azure AD Service Principal Authentication ESCU actions · alerting P Azure AD Successful PowerShell Authentication ESCU actions · alerting P Azure AD Successful Single-Factor Authentication ESCU actions · alerting P Azure Runbook Webhook Created ESCU actions · alerting P Cloud Compute Instance Created By Previously Unseen User ESCU actions · hunting P Cloud Instance Modified By Previously Unseen User ESCU actions · hunting P GCP Authentication Failed During MFA Challenge ESCU actions · alerting P GCP Multiple Failed MFA Requests For User ESCU actions · alerting P GCP Successful Single-Factor Authentication ESCU actions · alerting P O365 Security And Compliance Alert Triggered ESCU actions · alerting P Windows Entra User Management Via Azure CLI ESCU actions · hunting P Abnormally High AWS Instances Launched by User ESCU actions · hunting P Abnormally High AWS Instances Launched by User - MLTK ESCU actions · hunting P Abnormally High AWS Instances Terminated by User ESCU actions · hunting P Abnormally High AWS Instances Terminated by User - MLTK ESCU actions · hunting P Abnormally High Number Of Cloud Infrastructure API Calls ESCU actions · hunting P Abnormally High Number Of Cloud Instances Destroyed ESCU actions · hunting P Abnormally High Number Of Cloud Instances Launched ESCU actions · hunting P Abnormally High Number Of Cloud Security Group API Calls ESCU actions · hunting P Detect AWS API Activities From Unapproved Accounts ESCU actions · hunting P Detect new API calls from user roles ESCU actions · hunting P Detect new user AWS Console Login ESCU actions · hunting P Detect Spike in AWS API Activity ESCU actions · hunting P Detect Spike in Security Group Activity ESCU actions · hunting P EC2 Instance Modified With Previously Unseen User ESCU actions · hunting P EC2 Instance Started With Previously Unseen User ESCU actions · hunting P [LLM] Entra helpdesk password reset immediately followed by new MFA method registration (ShinyHunters ATO) Bespoke install · alerting SPDD [LLM] New attacker device registered/joined to Microsoft Entra ID Bespoke install · hunting DSΣPDD [LLM] SSO application-access burst — one identity authenticating to many distinct SaaS apps in a short window Bespoke actions · alerting DSPDD [LLM] Permissive RBAC grants create on logging-operator flows/outputs resources Bespoke delivery · hunting SΣPDD [LLM] Exposed-credential reuse: one identity authenticating to 3+ distinct cloud services within 1 hour Bespoke actions · alerting DSDDCW [LLM] Budibase OIDC login sequence (configs → callback → self) from single source Bespoke exploit · hunting SP [LLM] IdP self-registration or profile email-change asserting a privileged Budibase user's email Bespoke actions · hunting SP [LLM] Salesforce API access bearing python-requests/aiohttp automation user-agent (Icarus OAuth abuse) Bespoke actions · alerting DSP [LLM] Salesforce connected-app OAuth access from first-seen ISP / anonymizing proxy (stolen-token reuse) Bespoke exploit · hunting DSP [LLM] Microsoft 365 OAuth device code authentication flow sign-in (EvilTokens) Bespoke exploit · hunting DSΣPDD [LLM] EvilTokens device-code token polling from attacker infra (python-requests UA / C2 IPs) Bespoke delivery · hunting DSΣPDD [LLM] Suspicious commit pattern: '[skip ci]' with backdated timestamp adding only IDE config files Bespoke delivery · hunting DSPDD [LLM] Lateral movement via aws ssm send-command or kubectl exec spawned by python/node Bespoke actions · alerting DSΣPDDCSCW [LLM] AWS IMDS (169.254.169.254) Hit from Developer / Non-EC2 Endpoint (Nx Console Credential Theft) Bespoke actions · hunting DSPDDCS [LLM] AWS SSM SendCommand Fan-out from EC2 Instance Role (TeamPCP Worm Propagation) Bespoke actions · hunting PDD [LLM] Mini Shai-Hulud dead-drop git commit authored as claude@users.noreply.github.com Bespoke actions · alerting DSΣPDDCS [LLM] Shai-Hulud preinstall: node/npm spawning git/curl/gh pushing to attacker repo or GitHub API Bespoke actions · hunting DSPDDCS [LLM] Kubernetes privileged-pod DaemonSet fan-out from compromised LiteLLM workload Bespoke actions · hunting SPDD [LLM] ServiceNow Virtual Agent Invocation of Hidden AIA-Agent Invoker AutoChat Topic (CVE-2025-12420) Bespoke exploit · alerting DSPDDCS [LLM] Cloud metadata service (IMDS) access from npm / node child process Bespoke actions · alerting DSPDDCS [LLM] Storage account key retrieval (listKeys) inside an ARM/Bicep deployment — secret-in-output leak vector Bespoke actions · hunting SPDD [LLM] WAF-Role EC2 instance credentials used from external IP (instance credential exfiltration) Bespoke actions · alerting PDDCW

Articles citing this technique (18)