// MITRE ATT&CK
T1098 · Account Manipulation
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups.(Citation: FireEye SMOKEDHAM June 2021) The...
How to detect & mitigate it
Detecting Account Manipulation starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (7)
T1098.001
Additional Cloud Credentials T1098.002
Additional Email Delegate Permissions T1098.003
Additional Cloud Roles T1098.004
SSH Authorized Keys T1098.005
Device Registration T1098.006
Additional Container Cluster Roles T1098.007
Additional Local or Domain Groups
Additional Cloud Credentials T1098.002
Additional Email Delegate Permissions T1098.003
Additional Cloud Roles T1098.004
SSH Authorized Keys T1098.005
Device Registration T1098.006
Additional Container Cluster Roles T1098.007
Additional Local or Domain Groups
Related techniques
T1037
Boot or Logon Initialization Scripts T1543
Create or Modify System Process T1133
External Remote Services T1547
Boot or Logon Autostart Execution T1547.014
Active Setup T1176.001
Browser Extensions T1543.003
Windows Service T1137
Office Application Startup
Boot or Logon Initialization Scripts T1543
Create or Modify System Process T1133
External Remote Services T1547
Boot or Logon Autostart Execution T1547.014
Active Setup T1176.001
Browser Extensions T1543.003
Windows Service T1137
Office Application Startup
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.