// MITRE ATT&CK

T1098.001 · Additional Cloud Credentials

🎯 Persistence IaaSIdentity ProviderSaaS Sub-technique

Sub-technique of T1098 · Account Manipulation.

Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment. For example, adversaries may add credentials for Service Principals and Applications in addition to existing legitimate credentials in Azure...

How to detect & mitigate it

Detecting Additional Cloud Credentials starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.