Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1098.001

T1098.001Additional Cloud Credentials

T1098.001 — Additional Cloud Credentials is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 8 detection use cases covering it and 79 threat-intel articles citing it.

PersistencePrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
8Use cases
79Articles
0Sub-techniques
2Tactics

Use cases covering this technique (8)

OAuth consent / suspicious app grant Internal actions · alerting DSΣP [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Internal exploit · alerting DSPDDCW Azure AD Service Principal New Client Credentials ESCU actions · alerting P O365 Service Principal New Client Credentials ESCU actions · alerting P [LLM] Budibase: API key minted via /api/global/self/api_key then /api/public/v1/roles/assign within 5m Bespoke exploit · alerting SPDD [LLM] nebula-mesh CVE-2026-47724 — cross-tenant host identity hijack via /hosts/{id}/reenroll → /enroll chain Bespoke install · alerting SPDD [LLM] Shadow Credentials: msDS-KeyCredentialLink attribute modification Bespoke install · alerting DSΣPDDCS

Articles citing this technique (79)