Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1078

T1078Valid Accounts

T1078 — Valid Accounts is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 83 detection use cases covering it and 23 threat-intel articles citing it.

Defense EvasionPersistencePrivilege EscalationInitial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
83Use cases
23Articles
4Sub-techniques
4Tactics

Sub-techniques (4)

Use cases covering this technique (83)

1Password impossible-travel sign-in Internal delivery · alerting DD Atlassian administrator impersonating user Internal actions · alerting DD Auth0 anomalous attack-protection event spike Internal delivery · alerting DD AWS Console login without MFA + impossible travel Internal delivery · alerting DDCW Credential-stuffing attack on application Internal delivery · alerting DD GitHub branch protection disabled with force-push bypass Internal install · alerting DD GitLab password reset from suspicious IP Internal delivery · alerting DD Impossible travel from application business-logic event Internal delivery · alerting DD [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) Internal exploit · alerting DSPDD [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Internal exploit · alerting DSPDDCW Cisco IOS XE WebUI Login From IOSd Local Port ESCU actions · alerting P Cisco IOS XE WebUI Programmatic Configuration ESCU actions · hunting P ESXi Account Modified ESCU actions · hunting P ESXi External Root Login Activity ESCU actions · hunting P ESXi Shared or Stolen Root Account ESCU actions · hunting P ESXi User Granted Admin Role ESCU actions · alerting P M365 Copilot Application Usage Pattern Anomalies ESCU actions · hunting P M365 Copilot Session Origin Anomalies ESCU actions · hunting P Okta Risk Threshold Exceeded ESCU actions · alerting P PingID Multiple Failed MFA Requests For User ESCU actions · alerting P Zoom High Video Latency ESCU actions · hunting P ASL AWS SAML Update identity provider ESCU actions · alerting P AWS Bedrock Invoke Model Access Denied ESCU actions · alerting P AWS SAML Update identity provider ESCU actions · alerting P Azure AD Multiple AppIDs and UserAgents Authentication Spike ESCU actions · hunting P Cloud API Calls From Previously Unseen User Roles ESCU actions · hunting P Cloud Provisioning Activity From Previously Unseen City ESCU actions · hunting P Cloud Provisioning Activity From Previously Unseen Country ESCU actions · hunting P Cloud Provisioning Activity From Previously Unseen IP Address ESCU actions · hunting P Cloud Provisioning Activity From Previously Unseen Region ESCU actions · hunting P GCP Detect gcploit framework ESCU actions · alerting P Geographic Improbable Location ESCU actions · hunting P O365 Multiple AppIDs and UserAgents Authentication Spike ESCU actions · hunting P Okta Non-Standard VPN Usage ESCU actions · alerting P Unusual Number of Computer Service Tickets Requested ESCU actions · hunting P Unusual Number of Remote Endpoint Authentication Events ESCU actions · hunting P Windows Azure PowerShell Module Installation Via PowerShell Script ESCU actions · hunting P Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script ESCU actions · alerting P Windows Large Number of Computer Service Tickets Requested ESCU actions · hunting P Windows Multiple Account Passwords Changed ESCU actions · alerting P Windows Multiple Accounts Deleted ESCU actions · alerting P Windows Multiple Accounts Disabled ESCU actions · alerting P Cisco IOS Suspicious Privileged Account Creation ESCU actions · hunting P Cisco Privileged Account Creation with HTTP Command Execution ESCU actions · alerting P Cisco Privileged Account Creation with Suspicious SSH Activity ESCU actions · alerting P Cisco Secure Firewall - High Priority Intrusion Classification ESCU actions · alerting P ASL AWS CreateAccessKey ESCU actions · hunting P aws detect attach to role policy ESCU actions · hunting P aws detect permanent key creation ESCU actions · hunting P aws detect role creation ESCU actions · hunting P aws detect sts assume role abuse ESCU actions · hunting P AWS SAML Access by Provider User and Principal ESCU actions · hunting P GCP Detect accounts with high risk roles by project ESCU actions · hunting P GCP Detect high risk permissions by resource and account ESCU actions · hunting P gcp detect oauth token abuse ESCU actions · hunting P Web Fraud - Anomalous User Clickspeed ESCU actions · hunting P [LLM] First successful FortiGate admin/SSL-VPN login from never-seen ASN after failure burst Bespoke exploit · hunting DSPDD [LLM] Ivanti Sentry unauthenticated admin account creation (CVE-2026-10523) Bespoke install · alerting DSPDDCS [LLM] SAP NetWeaver SAML XML signature wrapping anomaly (CVE-2026-44748) Bespoke exploit · hunting DSPDD [LLM] Admin / privileged API call without a preceding SUCCESSFUL login (JWT forgery indicator) Bespoke actions · hunting DSPDDCW [LLM] Anomalous Host header to LiteLLM (Starlette CVE-2026-48710 BadHost bypass) Bespoke exploit · hunting SPDD [LLM] pfSense / firewall config change enabling Web SSL VPN after admin login Bespoke install · hunting SPDD [LLM] DbGate exploit chain: anonymous /auth/login + /api/archive/unzip POSTs from same source (CVE-2026-47669) Bespoke exploit · alerting SΣPDD [LLM] GitHub bulk git tag force-push by single actor across multiple org repos Bespoke delivery · hunting PDD [LLM] praisonai-platform: identity-swap chain — owner grant followed by login from the granted account Bespoke actions · hunting DSPDD [LLM] praisonai-platform cross-tenant workspace operations from single source IP Bespoke actions · alerting DSPDD [LLM] PraisonAI Platform member role mutation endpoint hit (CVE-2026-47407 privilege escalation) Bespoke actions · alerting SΣPDDCW [LLM] PraisonAI Platform open-registration burst followed by workspace privileged action Bespoke delivery · alerting SPDDCW [LLM] Yamcs MDB algorithm PATCH with embedded Jython java.lang.Runtime payload (CVE-2026-46621) Bespoke exploit · alerting DSΣPDDCS [LLM] Nezha CVE-2026-46716 exploit: POST /api/v1/cron with empty servers + CronCoverAll Bespoke exploit · alerting SΣPDD [LLM] YesWiki Bazar form-import volumetric POST — CVE-2026-46670 blind SQLi extraction loop Bespoke exploit · alerting SP [LLM] HAXcms CVE-2026-46395: forged-JWT admin write within 30m of connectionSettings leak Bespoke actions · alerting DSP [LLM] phpMyFAQ 2FA bypass success: /admin/check brute burst followed by authenticated /admin/ access Bespoke install · alerting SP [LLM] MCPHub SSE endpoint accessed with arbitrary username in URL path (CVE-2025/GHSA-wf8q-wvv8-p8jf hunt) Bespoke exploit · hunting SΣPDD [LLM] MCPHub identity spoofing — admin-themed username in /<user>/sse path Bespoke exploit · alerting SΣPDD [LLM] MCPHub SSE user-segment fan-out — single source spawning sessions under multiple usernames Bespoke recon · alerting SPDD [LLM] MCPHub tool execution via spoofed identity — POST to /<user>/messages with JSON-RPC body Bespoke actions · alerting SΣPDD [LLM] Strapi CVE-2026-27886 admin takeover — exploit burst followed by `/admin/reset-password` POST Bespoke actions · alerting SPDD [LLM] tj-actions/changed-files compromised commit SHA referenced in workflow YAML or git history Bespoke weapon · alerting DSΣPDDCS [LLM] Sha1-Hulud npm Worm — Self-Hosted GitHub Actions Runner Registration with Name 'SHA1HULUD' Bespoke install · alerting DSΣPDD [LLM] Internal workflows pulling aws-actions/configure-aws-credentials@v4.3.0 during the buggy-release window Bespoke delivery · hunting SPDD [LLM] Next.js CVE-2025-29927 middleware bypass via x-middleware-subrequest header Bespoke exploit · alerting DSΣPDDCS [LLM] Git checkout of compromised tj-actions/changed-files commit on runner host Bespoke weapon · hunting DSPDDCS

Articles citing this technique (23)