T1078.004sub-technique of T1078 Valid Accounts

Cloud Accounts

IaaS · Identity Provider · Office Suite · SaaS18 pieces on this siteT1078.004 on attack.mitre.org

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application.

MITRE ATT&CK 19.2, retrieved 2026-09-12

If this is happening now

10

Checklists and playbooks to open while the alert is still live.

First-hour playbookMembers

Cloud account compromise

Impossible travel, an unrecognised inbox rule, or a reported invoice-fraud attempt.

T1078.004
First-hour playbookMembers

A credential is public

A secret scanner alert, a report from a researcher, or finding a key in a public repository.

T1078.004
First-hour playbook

Somebody talked the help desk into a reset

The service desk reset a password or an MFA method for a caller, and the real user says it was not them. Or a new MFA method appeared on an account straight after a help desk ticket.

T1078.004
First-hour playbook

A leaver's account is still being used

Sign-ins, mailbox activity or VPN sessions on the account of somebody who has left, or of a contractor whose engagement has ended.

T1078T1078.004

Detect it

2

Hunts and rules you can run, each stating what it needs and what else it returns.

The evidence it leaves

2

Where the traces live, and what each source proves and does not.

Practise it

2

Labs, timelines, evidence packs and tabletop scenarios to work before you need to.

Guided labMembersCONSTRUCTED

Guided lab: the mailbox rule that was not the point

A business email compromise where the obvious finding is a decoy. Ninety minutes on Microsoft 365 audit logs, OAuth consent grants, and why resetting the password does not end this incident.

T1078.004
TabletopCONSTRUCTED

Impossible travel, and then a mailbox rule

You have fifteen minutes. What are your first three queries, in order, and what single action do you take before any of them? Write down what you expect each query to return before you run it.

T1078.004

Read

2

Analyses, case studies, guides, references and interview questions.

AnalysisCONSTRUCTED

Evidence Gap Challenge No. 1: the laptop was reimaged on Tuesday

A supplier is out €96,000 and the only endpoint that mattered was wiped on day one, by a helpdesk following the documented process correctly. Here is every artefact that still exists. Work out what you can prove, what you can only say is consistent, and the one collection change that would have moved the most from the second column to the first.

T1078.004

how MITRE says to see it

Detection of Abused or Compromised Cloud Accounts for Access and Persistence

  • Detects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts.
  • Detects cloud account use for API calls that exceed normal scope, such as IAM changes or access to services never used before.
  • Detects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users.
  • Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles.

what reduces it

  • M1017 User Training. Applications may send push notifications to verify a login as a form of multi-factor authentication (MFA). Train users to only accept valid push notifications and to report suspicious push notifications.
  • M1027 Password Policies. Ensure that cloud accounts, particularly privileged accounts, have complex, unique passwords across all systems on the network. Passwords and access keys should be rotated regularly. This limits the amount of time credentials can be used to access resources if a credential is compromised without your knowledge.
  • M1018 User Account Management. Periodically review user accounts and remove those that are inactive or unnecessary. Limit the ability for user accounts to create additional accounts.
  • M1026 Privileged Account Management. Review privileged cloud account permission levels routinely to look for those that could allow an adversary to gain wide access, such as Global Administrator and Privileged Role Administrator in Azure AD. These reviews should also check if new privileged cloud accounts have been created that were not authorized.
  • M1032 Multi-factor Authentication. Use multi-factor authentication for cloud accounts, especially privileged accounts. This can be implemented in a variety of forms (e.g. hardware, virtual, SMS), and can also be audited using administrative reporting features.
  • M1015 Active Directory Configuration. Disable legacy authentication, which does not support MFA, and require the use of modern authentication protocols instead.

the rest of T1078

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.