T1078.004Cloud Accounts
T1078.004 — Cloud Accounts is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 74 detection use cases covering it and 23 threat-intel articles citing it.
Defense EvasionPersistencePrivilege EscalationInitial Access
74Use cases
23Articles
0Sub-techniques
4Tactics
↑ Parent technique: T1078 · Valid Accounts
Use cases covering this technique (74)
Abnormal Security: login from new location Auth0 impossible-travel sign-in Impossible travel observed for IAM user AWS root account activity (any action) Azure AD brute-force login Datadog suspicious login GitHub PAT used from impossible-travel locations Google Workspace service account modifying group membership [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes [WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Okta Authentication Failed During MFA Challenge Okta Successful Single Factor Authentication Okta ThreatInsight Threat Detected ASL AWS Create Policy Version to allow all resources AWS Create Policy Version to allow all resources AWS SetDefaultPolicyVersion AWS Successful Single-Factor Authentication Azure AD Authentication Failed During MFA Challenge Azure AD Multiple Failed MFA Requests For User Azure AD Service Principal Authentication Azure AD Successful PowerShell Authentication Azure AD Successful Single-Factor Authentication Azure Runbook Webhook Created Cloud Compute Instance Created By Previously Unseen User Cloud Instance Modified By Previously Unseen User GCP Authentication Failed During MFA Challenge GCP Multiple Failed MFA Requests For User GCP Successful Single-Factor Authentication O365 Security And Compliance Alert Triggered Windows Entra User Management Via Azure CLI Abnormally High AWS Instances Launched by User Abnormally High AWS Instances Launched by User - MLTK Abnormally High AWS Instances Terminated by User Abnormally High AWS Instances Terminated by User - MLTK Abnormally High Number Of Cloud Infrastructure API Calls Abnormally High Number Of Cloud Instances Destroyed Abnormally High Number Of Cloud Instances Launched Abnormally High Number Of Cloud Security Group API Calls Detect AWS API Activities From Unapproved Accounts Detect new API calls from user roles Detect new user AWS Console Login Detect Spike in AWS API Activity Detect Spike in Security Group Activity EC2 Instance Modified With Previously Unseen User EC2 Instance Started With Previously Unseen User [LLM] Entra ID password spray: many distinct accounts failing auth from few source IPs [LLM] Entra ID MFA fatigue: burst of MFA-challenge failures followed by a successful MFA sign-in [LLM] First-time Entra directory enumeration via Graph/PowerShell CLI tooling by a user [LLM] Post-quishing cloud token replay: MFA-satisfied sign-in shortly after QR-attachment email [LLM] Stolen credentials reused from TeamPCP C2 IP in AWS CloudTrail [LLM] AiTM MFA-relay: successful Entra sign-in from AWS EC2 / hosting ASN [LLM] AI resource key creation paired with logging/alert teardown in cloud control plane [LLM] Entra ID sign-in or session from Storm-2945 AiTM device-code phishing infrastructure [LLM] OAuth device-code authorization flow sign-in (ARToken/EvilTokens MFA bypass) [LLM] Budibase OIDC login sequence (configs → callback → self) from single source [LLM] IdP self-registration or profile email-change asserting a privileged Budibase user's email [LLM] Gitea PR head-branch update via API v1 pulls/{index}/update (CVE-2026-58443 exploit vector) [LLM] Salesforce API access bearing python-requests/aiohttp automation user-agent (Icarus OAuth abuse) [LLM] Salesforce connected-app OAuth access from first-seen ISP / anonymizing proxy (stolen-token reuse) [LLM] Microsoft 365 OAuth device code authentication flow sign-in (EvilTokens) [LLM] EvilTokens device-code token polling from attacker infra (python-requests UA / C2 IPs) [LLM] Suspicious commit pattern: '[skip ci]' with backdated timestamp adding only IDE config files [LLM] Lateral movement via aws ssm send-command or kubectl exec spawned by python/node [LLM] AWS IMDS (169.254.169.254) Hit from Developer / Non-EC2 Endpoint (Nx Console Credential Theft) [LLM] AWS SSM SendCommand Fan-out from EC2 Instance Role (TeamPCP Worm Propagation) [LLM] Mini Shai-Hulud dead-drop git commit authored as claude@users.noreply.github.com [LLM] Shai-Hulud preinstall: node/npm spawning git/curl/gh pushing to attacker repo or GitHub API [LLM] Kubernetes privileged-pod DaemonSet fan-out from compromised LiteLLM workload [LLM] ServiceNow Virtual Agent Invocation of Hidden AIA-Agent Invoker AutoChat Topic (CVE-2025-12420) [LLM] Cloud metadata service (IMDS) access from npm / node child process [LLM] Storage account key retrieval (listKeys) inside an ARM/Bicep deployment — secret-in-output leak vector [LLM] WAF-Role EC2 instance credentials used from external IP (instance credential exfiltration)Articles citing this technique (23)
crit Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List. art-35