Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1078.004

T1078.004Cloud Accounts

T1078.004 — Cloud Accounts is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 74 detection use cases covering it and 23 threat-intel articles citing it.

Defense EvasionPersistencePrivilege EscalationInitial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
74Use cases
23Articles
0Sub-techniques
4Tactics

Use cases covering this technique (74)

Abnormal Security: login from new location Internal delivery · alerting DD Auth0 impossible-travel sign-in Internal delivery · alerting DD Impossible travel observed for IAM user Internal delivery · alerting DDCW AWS root account activity (any action) Internal delivery · alerting DDCW Azure AD brute-force login Internal delivery · alerting DD Datadog suspicious login Internal delivery · alerting DD GitHub PAT used from impossible-travel locations Internal delivery · alerting DD Google Workspace service account modifying group membership Internal install · alerting DD [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Internal exploit · alerting DSPDDCW [WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Internal actions · alerting DSPDD Okta Authentication Failed During MFA Challenge ESCU actions · alerting P Okta Successful Single Factor Authentication ESCU actions · hunting P Okta ThreatInsight Threat Detected ESCU actions · hunting P ASL AWS Create Policy Version to allow all resources ESCU actions · alerting P AWS Create Policy Version to allow all resources ESCU actions · alerting P AWS SetDefaultPolicyVersion ESCU actions · alerting P AWS Successful Single-Factor Authentication ESCU actions · alerting P Azure AD Authentication Failed During MFA Challenge ESCU actions · alerting P Azure AD Multiple Failed MFA Requests For User ESCU actions · alerting P Azure AD Service Principal Authentication ESCU actions · alerting P Azure AD Successful PowerShell Authentication ESCU actions · alerting P Azure AD Successful Single-Factor Authentication ESCU actions · alerting P Azure Runbook Webhook Created ESCU actions · alerting P Cloud Compute Instance Created By Previously Unseen User ESCU actions · hunting P Cloud Instance Modified By Previously Unseen User ESCU actions · hunting P GCP Authentication Failed During MFA Challenge ESCU actions · alerting P GCP Multiple Failed MFA Requests For User ESCU actions · alerting P GCP Successful Single-Factor Authentication ESCU actions · alerting P O365 Security And Compliance Alert Triggered ESCU actions · alerting P Windows Entra User Management Via Azure CLI ESCU actions · hunting P Abnormally High AWS Instances Launched by User ESCU actions · hunting P Abnormally High AWS Instances Launched by User - MLTK ESCU actions · hunting P Abnormally High AWS Instances Terminated by User ESCU actions · hunting P Abnormally High AWS Instances Terminated by User - MLTK ESCU actions · hunting P Abnormally High Number Of Cloud Infrastructure API Calls ESCU actions · hunting P Abnormally High Number Of Cloud Instances Destroyed ESCU actions · hunting P Abnormally High Number Of Cloud Instances Launched ESCU actions · hunting P Abnormally High Number Of Cloud Security Group API Calls ESCU actions · hunting P Detect AWS API Activities From Unapproved Accounts ESCU actions · hunting P Detect new API calls from user roles ESCU actions · hunting P Detect new user AWS Console Login ESCU actions · hunting P Detect Spike in AWS API Activity ESCU actions · hunting P Detect Spike in Security Group Activity ESCU actions · hunting P EC2 Instance Modified With Previously Unseen User ESCU actions · hunting P EC2 Instance Started With Previously Unseen User ESCU actions · hunting P [LLM] Entra ID password spray: many distinct accounts failing auth from few source IPs Bespoke exploit · alerting DSPDD [LLM] Entra ID MFA fatigue: burst of MFA-challenge failures followed by a successful MFA sign-in Bespoke exploit · alerting DSPDD [LLM] First-time Entra directory enumeration via Graph/PowerShell CLI tooling by a user Bespoke actions · hunting DSPDD [LLM] Post-quishing cloud token replay: MFA-satisfied sign-in shortly after QR-attachment email Bespoke actions · alerting DSPDD [LLM] Stolen credentials reused from TeamPCP C2 IP in AWS CloudTrail Bespoke actions · alerting ΣPDDCW [LLM] AiTM MFA-relay: successful Entra sign-in from AWS EC2 / hosting ASN Bespoke actions · hunting DSPDD [LLM] AI resource key creation paired with logging/alert teardown in cloud control plane Bespoke install · hunting SPDDCW [LLM] Entra ID sign-in or session from Storm-2945 AiTM device-code phishing infrastructure Bespoke actions · hunting DSΣPDD [LLM] OAuth device-code authorization flow sign-in (ARToken/EvilTokens MFA bypass) Bespoke exploit · hunting DSΣ [LLM] Budibase OIDC login sequence (configs → callback → self) from single source Bespoke exploit · hunting SP [LLM] IdP self-registration or profile email-change asserting a privileged Budibase user's email Bespoke actions · hunting SP [LLM] Gitea PR head-branch update via API v1 pulls/{index}/update (CVE-2026-58443 exploit vector) Bespoke exploit · hunting SΣP [LLM] Salesforce API access bearing python-requests/aiohttp automation user-agent (Icarus OAuth abuse) Bespoke actions · alerting DSP [LLM] Salesforce connected-app OAuth access from first-seen ISP / anonymizing proxy (stolen-token reuse) Bespoke exploit · hunting DSP [LLM] Microsoft 365 OAuth device code authentication flow sign-in (EvilTokens) Bespoke exploit · hunting DSΣPDD [LLM] EvilTokens device-code token polling from attacker infra (python-requests UA / C2 IPs) Bespoke delivery · hunting DSΣPDD [LLM] Suspicious commit pattern: '[skip ci]' with backdated timestamp adding only IDE config files Bespoke delivery · hunting DSPDD [LLM] Lateral movement via aws ssm send-command or kubectl exec spawned by python/node Bespoke actions · alerting DSΣPDDCSCW [LLM] AWS IMDS (169.254.169.254) Hit from Developer / Non-EC2 Endpoint (Nx Console Credential Theft) Bespoke actions · hunting DSPDDCS [LLM] AWS SSM SendCommand Fan-out from EC2 Instance Role (TeamPCP Worm Propagation) Bespoke actions · hunting PDD [LLM] Mini Shai-Hulud dead-drop git commit authored as claude@users.noreply.github.com Bespoke actions · alerting DSΣPDDCS [LLM] Shai-Hulud preinstall: node/npm spawning git/curl/gh pushing to attacker repo or GitHub API Bespoke actions · hunting DSPDDCS [LLM] Kubernetes privileged-pod DaemonSet fan-out from compromised LiteLLM workload Bespoke actions · hunting SPDD [LLM] ServiceNow Virtual Agent Invocation of Hidden AIA-Agent Invoker AutoChat Topic (CVE-2025-12420) Bespoke exploit · alerting DSPDDCS [LLM] Cloud metadata service (IMDS) access from npm / node child process Bespoke actions · alerting DSPDDCS [LLM] Storage account key retrieval (listKeys) inside an ARM/Bicep deployment — secret-in-output leak vector Bespoke actions · hunting SPDD [LLM] WAF-Role EC2 instance credentials used from external IP (instance credential exfiltration) Bespoke actions · alerting PDDCW

Articles citing this technique (23)