Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Lateral Movement/ T1550.001

T1550.001Application Access Token

T1550.001 — Application Access Token is a MITRE ATT&CK technique in the Lateral Movement tactic. Clankerusecase tracks 21 detection use cases covering it and 13 threat-intel articles citing it.

Lateral Movement
View on the matrix → Filter Detection Library MITRE official spec ↗
21Use cases
13Articles
0Sub-techniques
1Tactic

Use cases covering this technique (21)

AWS brute-force ConsoleLogin then AssumeRole Internal delivery · alerting DDCW GitHub PAT used from impossible-travel locations Internal delivery · alerting DD Google Workspace OAuth key making account changes Internal install · alerting DD [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD [WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Internal actions · alerting DSPDD [LLM] OWAReaper OAuth token theft via OWA service.svc GetClientAccessToken (IIS) Bespoke actions · hunting SP [LLM] Suspicious OAuth application consent granting broad scopes (ShinyHunters DataLoader-style persistence) Bespoke c2 · hunting DSΣPDD [LLM] Exposed-credential reuse: one identity authenticating to 3+ distinct cloud services within 1 hour Bespoke actions · alerting DSDDCW [LLM] Victim account takeover: new-IP sign-in within 1h of redirect_uri mismatch (CVE-2026-54588) Bespoke actions · alerting DSP [LLM] Better-Auth SCIM global user deletion via /scim/v2/Users from unsanctioned caller Bespoke actions · hunting SΣP [LLM] Better-Auth SCIM profile/email rewrite fan-out across many /scim/v2/Users resources Bespoke actions · hunting SP [LLM] Gitea PR head-branch update via public base-repo route (CVE-2026-58443) Bespoke exploit · hunting SΣP [LLM] Gitea Actions V4 artifact signed-URL HMAC reuse across distinct taskID/artifactName tuples (CVE-2026-58426) Bespoke exploit · alerting SP [LLM] Anomalous DLL-host process reaching Microsoft Graph/login.microsoftonline for calendar C2 Bespoke c2 · hunting DSΣPDDCS [LLM] Envoy Gateway ServiceAccount token reuse for anomalous K8s API actions Bespoke actions · hunting SΣPDD [LLM] TSDProxy x-tsdproxy-auth-token leaked to backend in upstream HTTP requests Bespoke exploit · hunting SPDD [LLM] TSDProxy management-port replay: loopback connection to 127.0.0.1:8080 by non-proxy process Bespoke exploit · alerting DSΣPCS [LLM] TSDProxy management API abuse: /api/v1 request with forged x-tsdproxy-id and auth token Bespoke actions · alerting SPDD [LLM] FileBrowser identity-cycling: 3+ user identities from one untrusted source in 5 min Bespoke exploit · alerting SP [LLM] 9router API key / secret exfiltration via /api/settings/database without prior login Bespoke actions · alerting SP

Articles citing this technique (13)