Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1078

T1078Valid Accounts

T1078 — Valid Accounts is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 82 detection use cases covering it and 19 threat-intel articles citing it.

Defense EvasionPersistencePrivilege EscalationInitial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
82Use cases
19Articles
4Sub-techniques
4Tactics

Sub-techniques (4)

Use cases covering this technique (82)

1Password impossible-travel sign-in Internal delivery · alerting DD Atlassian administrator impersonating user Internal actions · alerting DD Auth0 anomalous attack-protection event spike Internal delivery · alerting DD AWS Console login without MFA + impossible travel Internal delivery · alerting DDCW Credential-stuffing attack on application Internal delivery · alerting DD GitHub branch protection disabled with force-push bypass Internal install · alerting DD GitLab password reset from suspicious IP Internal delivery · alerting DD Impossible travel from application business-logic event Internal delivery · alerting DD [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) Internal exploit · alerting DSPDD [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Internal exploit · alerting DSPDDCW Cisco IOS XE WebUI Login From IOSd Local Port ESCU actions · alerting P Cisco IOS XE WebUI Programmatic Configuration ESCU actions · hunting P ESXi Account Modified ESCU actions · hunting P ESXi External Root Login Activity ESCU actions · hunting P ESXi Shared or Stolen Root Account ESCU actions · hunting P ESXi User Granted Admin Role ESCU actions · alerting P M365 Copilot Application Usage Pattern Anomalies ESCU actions · hunting P M365 Copilot Session Origin Anomalies ESCU actions · hunting P Okta Risk Threshold Exceeded ESCU actions · alerting P PingID Multiple Failed MFA Requests For User ESCU actions · alerting P Splunk User Enumeration Attempt ESCU actions · alerting P Zoom High Video Latency ESCU actions · hunting P ASL AWS SAML Update identity provider ESCU actions · alerting P AWS Bedrock Invoke Model Access Denied ESCU actions · alerting P AWS SAML Update identity provider ESCU actions · alerting P Azure AD Multiple AppIDs and UserAgents Authentication Spike ESCU actions · hunting P Cloud API Calls From Previously Unseen User Roles ESCU actions · hunting P Cloud Provisioning Activity From Previously Unseen City ESCU actions · hunting P Cloud Provisioning Activity From Previously Unseen Country ESCU actions · hunting P Cloud Provisioning Activity From Previously Unseen IP Address ESCU actions · hunting P Cloud Provisioning Activity From Previously Unseen Region ESCU actions · hunting P GCP Detect gcploit framework ESCU actions · alerting P Geographic Improbable Location ESCU actions · hunting P O365 Multiple AppIDs and UserAgents Authentication Spike ESCU actions · hunting P Okta Non-Standard VPN Usage ESCU actions · alerting P Unusual Number of Computer Service Tickets Requested ESCU actions · hunting P Unusual Number of Remote Endpoint Authentication Events ESCU actions · hunting P Windows Azure PowerShell Module Installation Via PowerShell Script ESCU actions · hunting P Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script ESCU actions · alerting P Windows Large Number of Computer Service Tickets Requested ESCU actions · hunting P Windows Multiple Account Passwords Changed ESCU actions · alerting P Windows Multiple Accounts Deleted ESCU actions · alerting P Windows Multiple Accounts Disabled ESCU actions · alerting P Cisco IOS Suspicious Privileged Account Creation ESCU actions · hunting P Cisco Privileged Account Creation with HTTP Command Execution ESCU actions · alerting P Cisco Privileged Account Creation with Suspicious SSH Activity ESCU actions · alerting P Cisco Secure Firewall - High Priority Intrusion Classification ESCU actions · alerting P ASL AWS CreateAccessKey ESCU actions · hunting P aws detect attach to role policy ESCU actions · hunting P aws detect permanent key creation ESCU actions · hunting P aws detect role creation ESCU actions · hunting P aws detect sts assume role abuse ESCU actions · hunting P AWS SAML Access by Provider User and Principal ESCU actions · hunting P GCP Detect accounts with high risk roles by project ESCU actions · hunting P GCP Detect high risk permissions by resource and account ESCU actions · hunting P gcp detect oauth token abuse ESCU actions · hunting P Web Fraud - Anomalous User Clickspeed ESCU actions · hunting P [LLM] Check Point SmartConsole admin login via forged application token (CVE-2026-16232) Bespoke exploit · hunting SΣP [LLM] Check Point security-policy change following external application-token admin login Bespoke actions · alerting SP [LLM] Multiple RMM agents co-resident on one host (BlueDash redundant access) Bespoke install · alerting DSPDDCS [LLM] OpenDJ SASL PLAIN bind invoking proxied authorization (authzid) — impersonation Bespoke exploit · hunting SΣPDD [LLM] OpenDJ proxied-auth fan-out — one source assuming many distinct authz identities Bespoke actions · hunting SPDD [LLM] Gitea same-user auth failure + success from different IPs within 2 minutes Bespoke exploit · alerting SP [LLM] Anomalous EnvoyExtensionPolicy submitter / suspicious policy name Bespoke delivery · hunting SΣPDD [LLM] First-seen SOAP client on MantisBT mantisconnect.php (new source, post-bypass admin activity) Bespoke exploit · hunting SP [LLM] n8n-MCP cross-tenant workflow version read/enumeration via n8n_workflow_versions (CVE-2026-54052) Bespoke recon · hunting SP [LLM] n8n-MCP vulnerable multi-tenant config exposure (ENABLE_MULTI_TENANT without version-tool mitigation) Bespoke exploit · hunting SP [LLM] FacturaScripts account takeover: /AdminPlugins access following filter[] SQLi from same source Bespoke actions · alerting SP [LLM] FileBrowser proxy-auth header forgery naming admin on /api/login Bespoke exploit · alerting SΣPDD [LLM] FileBrowser post-bypass admin API actions (DELETE/PUT /api/users, /api/settings) Bespoke actions · hunting SΣP [LLM] FileBrowser identity-cycling: 3+ user identities from one untrusted source in 5 min Bespoke exploit · alerting SP [LLM] External browser process connects to SiYuan kernel loopback admin port 127.0.0.1:6806 Bespoke exploit · hunting DSΣPDDCS [LLM] phpBB CVE-2026-48611 auth bypass via login_link auth_provider=apache Bespoke exploit · alerting SΣP [LLM] phpBB CVE-2026-48611 post-exploit ACP access from exploiting IP Bespoke actions · alerting SP [LLM] HTTP Basic Authorization header sent to phpBB login_link endpoint Bespoke exploit · hunting SP [LLM] Mautic campaign import ZIP upload — POST to campaign import endpoint Bespoke delivery · hunting SP [LLM] FortiBleed MSSQL login-failure burst then success (internet-exposed SQL spraying) Bespoke exploit · alerting DSP [LLM] phpBB ACP access from a source IP with no prior login (CVE-2026-48611 session hijack) Bespoke exploit · hunting SP [LLM] GitHub bulk git tag force-push by single actor across multiple org repos Bespoke delivery · hunting PDD [LLM] Next.js CVE-2025-29927 middleware bypass via x-middleware-subrequest header Bespoke exploit · alerting DSΣPDDCS [LLM] Git checkout of compromised tj-actions/changed-files commit on runner host Bespoke weapon · hunting DSPDDCS [LLM] Reuse of CircleCI-exfiltrated secrets / stolen SSO session from breach attacker IPs Bespoke actions · hunting DSΣPDDCSCW

Articles citing this technique (19)