kevmap

TechniquesT1087.004 › AN1090

AN1090 Analytic 1090

SaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Access to organizational directories via Google Workspace Directory API, Slack SCIM, or Okta SCIM by apps or identities outside normal roles.</p>
Detects
T1087.004 Cloud Account
Part of
DET0386 Cloud Account Enumeration via API, CLI, and Scripting Interfaces

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
Google Admin Auditusers.list, groups.listDC0013 User Account Metadata
saas:oktaSystem API Call: user.read, group.readDC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
APIRequestRateDetect rapid enumeration attempts or recursive group expansion.
AppIntegrationIDTag expected SCIM clients and suppress false positives from enterprise sync tools.
GeoContextTrigger alerts if enumeration occurs from anomalous IPs or regions.