T1098.005Device Registration
T1098.005 — Device Registration is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 10 detection use cases covering it and 3 threat-intel articles citing it.
PersistencePrivilege Escalation
10Use cases
3Articles
0Sub-techniques
2Tactics
↑ Parent technique: T1098 · Account Manipulation
Use cases covering this technique (10)
[WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Okta New Device Enrolled on Account PingID Mismatch Auth Source and Verification Response PingID New MFA Method After Credential Reset PingID New MFA Method Registered For User Azure AD New MFA Method Registered O365 New MFA Method Registered [LLM] New attacker device registered/joined to Microsoft Entra ID [LLM] Entra ID device registration = ARToken PRT persistence after device-code token theft [LLM] Iran-aligned MFA push-bombing followed by new auth method registered (AA24-290A)Articles citing this technique (3)
high Catan and Mouse art-261