kevmap

TechniquesT1136.003 › AN0899

AN0899 Analytic 0899

Identity Provider · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Adversaries create user accounts via identity provider APIs or admin portals (e.g., Azure AD, Okta). These accounts may be assigned elevated privileges or used in chained authentication. Detection monitors Add User activity from suspicious IPs or automation sources, followed by role/permission escalation.</p>
Detects
T1136.003 Cloud Account
Part of
DET0319 Detection Strategy for T1136.003 - Cloud Account Creation across IaaS, IdP, SaaS, Office

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
azure:auditAdd userDC0014 User Account Creation
azure:auditAdd member to roleDC0010 User Account Modification
azure:signinlogsLogin from newly created accountDC0002 User Account Authentication

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
IPAddressFilter on IPs outside known admin networks or geographies
RoleThresholdRaise alert if total admins exceeds historical baseline
ServicePrincipalFlagDifferentiate between user and service principal creation