Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Lateral Movement/ T1550.001

T1550.001Application Access Token

T1550.001 — Application Access Token is a MITRE ATT&CK technique in the Lateral Movement tactic. Clankerusecase tracks 21 detection use cases covering it and 10 threat-intel articles citing it.

Lateral Movement
View on the matrix → Filter Detection Library MITRE official spec ↗
21Use cases
10Articles
0Sub-techniques
1Tactic

Use cases covering this technique (21)

AWS brute-force ConsoleLogin then AssumeRole Internal delivery · alerting DDCW GitHub PAT used from impossible-travel locations Internal delivery · alerting DD Google Workspace OAuth key making account changes Internal install · alerting DD [WEEKLY] Dev/CI Toolchain Credential Read + Egress to Non-Canonical Registry Internal actions · alerting DSPDDCS [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD [WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Internal actions · alerting DSPDD [LLM] Stolen credentials reused from TeamPCP C2 IP in AWS CloudTrail Bespoke actions · alerting ΣPDDCW [LLM] Transfer-station client fingerprint: Go-http-client/2.0,gzip(gfe) user-agent in web egress Bespoke c2 · hunting SΣP [LLM] Victim account takeover: new-IP sign-in within 1h of redirect_uri mismatch (CVE-2026-54588) Bespoke actions · alerting DSP [LLM] Better-Auth SCIM global user deletion via /scim/v2/Users from unsanctioned caller Bespoke actions · hunting SΣP [LLM] Better-Auth SCIM profile/email rewrite fan-out across many /scim/v2/Users resources Bespoke actions · hunting SP [LLM] Gitea PR head-branch update via API v1 pulls/{index}/update (CVE-2026-58443 exploit vector) Bespoke exploit · hunting SΣP [LLM] Gitea Actions V4 artifact signed-URL forgery via oversized artifactID (CVE-2026-58426) Bespoke exploit · alerting SΣP [LLM] Gitea artifact HMAC signature reused across mismatched task/artifact tuples (CVE-2026-58426) Bespoke exploit · alerting SP [LLM] Gitea runner enumerating cross-task DownloadArtifact contexts (CVE-2026-58426 read path) Bespoke actions · hunting SP [LLM] Envoy Gateway ServiceAccount token reuse for anomalous K8s API actions Bespoke actions · hunting SΣPDD [LLM] TSDProxy x-tsdproxy-auth-token leaked to backend in upstream HTTP requests Bespoke exploit · hunting SPDD [LLM] TSDProxy management-port replay: loopback connection to 127.0.0.1:8080 by non-proxy process Bespoke exploit · alerting DSΣPCS [LLM] TSDProxy management API abuse: /api/v1 request with forged x-tsdproxy-id and auth token Bespoke actions · alerting SPDD [LLM] FileBrowser identity-cycling: 3+ user identities from one untrusted source in 5 min Bespoke exploit · alerting SP

Articles citing this technique (10)