// MITRE ATT&CK

T1550.001 · Application Access Token

🎯 Lateral Movement ContainersIaaSIdentity ProviderOffice SuiteSaaS Sub-technique

Sub-technique of T1550 · Use Alternate Authentication Material.

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials. Application access tokens are...

How to detect & mitigate it

Detecting Application Access Token starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.