// MITRE ATT&CK

T1098.003 · Additional Cloud Roles

🎯 Persistence IaaSIdentity ProviderOffice SuiteSaaS Sub-technique

Sub-technique of T1098 · Account Manipulation.

An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments.(Citation: AWS IAM Polici...

How to detect & mitigate it

Detecting Additional Cloud Roles starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.