Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1087.004

T1087.004Cloud Account

T1087.004 — Cloud Account is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 7 detection use cases covering it and 2 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
7Use cases
2Articles
0Sub-techniques
1Tactic

Use cases covering this technique (7)

AWS root account activity (any action) Internal delivery · alerting DDCW Okta IDP Lifecycle Modifications ESCU actions · hunting P Okta Unauthorized Access to Application ESCU actions · hunting P Azure AD AzureHound UserAgent Detected ESCU actions · alerting P Azure AD Service Principal Enumeration ESCU actions · alerting P [LLM] Bulk Matrix profile/room-member enumeration against Tchap endpoint Bespoke recon · hunting DSPDDCS [LLM] praisonai-platform CVE-2026-47416: Bulk agent/issue/project/comment enumeration immediately after a workspace role-change PATCH Bespoke actions · hunting SPDD

Articles citing this technique (2)