Account Manipulation: Device Registration T1098.005
Tactics: Persistence, Privilege Escalation
Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Authoring guide
These 27 rules share fields, values, and exclusions.
Fields filtered most (73 distinct)
These fields appear most often in rule filters.
Top indicator values (189 distinct)
These values appear most often in rule predicates.
Exclusions (19 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 1 rule
Elastic 19 rules
- AWS IAM Virtual MFA Device Registration Attempt with Session Token
- Entra ID ADRS Token Request by Microsoft Authentication Broker
- Entra ID AiTM Phishing-Kit Chain Detected
- Entra ID Device Registration with Phishing Kit Default OS Build
- Entra ID Device Registration with ROADtools Default OS Build
- Entra ID Device with ROADtools Default OS Build (Entity Analytics)
- Entra ID Microsoft Authentication Broker DRS Sign-In from Suspicious ASN
- Entra ID Multiple Device Registrations by a Single User
- Entra ID OAuth PRT Issuance to Non-Managed Device Detected
- Entra ID Phishing Kit Default OS Build (Entity Analytics)
- Entra ID Protection User Alert and Device Registration
- Entra ID Register Device with Unusual User Agent (Azure AD Join)
- Entra ID Unusual Cloud Device Registration
- Entra ID User Sign-in with Unusual Non-Managed Device
- Google Workspace Device Registration After OAuth from Suspicious ASN
- Google Workspace Device Registration Burst for Single User
- Google Workspace User Sign-in from Atypical Device Type
- M365 Exchange MFA Notification Email Deleted or Moved
- M365 Identity OAuth Flow by User Sign-in to Device Registration
Splunk 6 rules
- Azure AD New MFA Method Registered
- O365 New MFA Method Registered
- Okta New Device Enrolled on Account
- PingID Mismatch Auth Source and Verification Response
- PingID New MFA Method After Credential Reset
- PingID New MFA Method Registered For User