Account Manipulation: Additional Cloud Credentials T1098.001
Tactics: Persistence, Privilege Escalation
Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.
Authoring guide
These 59 rules share fields, values, and exclusions.
Fields filtered most (84 distinct)
These fields appear most often in rule filters.
Top indicator values (167 distinct)
These values appear most often in rule predicates.
Exclusions (25 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 8 rules
- Added Credentials to Existing Application
- API Key Created
- Attempt To Create API Key
- Github Outside Collaborator Detected
- IAM Access Key Created
- IAM Access Key Creation Attempt
- IAM Login Profile Created
- Okta Identity Provider Created
Elastic 26 rules
- Application Added to Google Workspace Domain
- Attempt to Create Okta API Token
- AWS EC2 Instance Interaction with IAM Service
- AWS First Occurrence of STS GetFederationToken Request by User
- AWS IAM Credentials Added to a Bedrock API Key Phantom User
- AWS IAM Login Profile Added for Root
- AWS IAM Login Profile Added to User
- AWS IAM Login Profile Created or Modified for an IAM User
- AWS IAM SAML Provider Created
- AWS IAM User Created Access Keys For Another User
- AWS IAM User Self-Created Access Key Subsequently Used
- AWS RDS DB Instance or Cluster Password Modified
- AWS Sensitive IAM Operations Performed via CloudShell
- Azure Storage Account Key Regenerated
- Entra ID Application Credential Modified
- Entra ID Domain Federation Configuration Change
- Entra ID Federated Identity Credential Issuer Modified
- Entra ID Service Principal Credentials Created by Unusual User
- Entra ID Service Principal Federated Credential Authentication by Unusual Client
- Entra ID Sharepoint or OneDrive Accessed by Unusual Client
- First Occurrence GitHub Event for a Personal Access Token (PAT)
- First Occurrence of Personal Access Token (PAT) Use For a GitHub User
- GCP Service Account Key Creation
- Google Workspace Object Copied from External Drive with App Consent
- New GitHub Personal Access Token (PAT) Added
- New User Added To GitHub Organization
Splunk 2 rules
Kusto 5 rules
- AWS Security Hub - Detect IAM root user Access Key existence
- AWSCloudTrail - Changes to internet facing AWS RDS Database instances
- AWSCloudTrail - Creation of Access Key for IAM User
- Detect credential add to Connect Sync Application
- New External User Granted Admin Role
YARA-L 6 rules
- Client Secret Added to Entra ID Application
- GitHub Personal Access Token Created from Tor IP Address
- GitHub Repository Deploy Key Created Or Modified
- Google Cloud Service Account Key Created or Uploaded
- O365 AD PowerShell App Login Subsequent Activity
- O365 Entra ID App Client Secret Added, Updated or Deleted
Panther 12 rules
- A Teleport Role was modified or created
- Anthropic Admin API Key Created
- Anthropic Admin API Key Deleted
- Anthropic Service Key Created
- Anthropic Service Key Revoked
- AWS Privilege Escalation Via User Compromise
- AWS User Takeover Via Password Reset
- Azure Service Principal Credentials Added
- Crowdstrike API Key Created
- Crowdstrike User Password Changed
- IAM Role Added to RDS Instance or Cluster
- Wiz User Role Updated Or Deleted