// MITRE ATT&CK

T1548.005 · Temporary Elevated Cloud Access

🎯 Privilege Escalation IaaSOffice SuiteIdentity Provider Sub-technique

Sub-technique of T1548 · Abuse Elevation Control Mechanism.

Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources. Many cloud environments allow administrators to grant user or service accounts permission to request just-in-time access to roles, impersonate other accounts, pass roles onto resou...

How to detect & mitigate it

Detecting Temporary Elevated Cloud Access starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.