{"id":"T1098.005","name":"Device Registration","url":"https://attack.mitre.org/techniques/T1098/005","tactics":["persistence","privilege-escalation"],"platforms":["Windows","Identity Provider"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0036","stix_id":"x-mitre-detection-strategy--bbeacdc8-c14c-44f1-9ace-fc8282a05c67","name":"Suspicious Device Registration via Entra ID or MFA Platform","url":"https://attack.mitre.org/detectionstrategies/DET0036","analytics":[{"id":"AN0103","stix_id":"x-mitre-analytic--108a10d2-4a9e-4c11-8a6f-42c8b60f0f52","name":"Analytic 0103","description":"Adversary registers new devices to compromised user accounts to bypass MFA or conditional access policies via Azure Entra ID, Okta, or Duo self-enrollment portals.","url":"https://attack.mitre.org/detectionstrategies/DET0036#AN0103","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:audit","channel":"Operation IN (\"Add device\", \"Add registered users to device\", \"Add registered owner to device\")","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"azure-audit"},{"name":"ApplicationLog:EntraIDPortal","channel":"DeviceRegistration events","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"applicationlog-entraidportal"},{"name":"azure:audit","channel":"New device object creation","data_component":"DC0087","data_component_name":"Active Directory Object Creation","log_source_slug":"azure-audit"}],"mutable_elements":[{"field":"ActorUserPrincipalName","description":"Define expected admin users to exclude known enrollment behavior"},{"field":"IP Address","description":"Scope internal vs. external device enrollment sources"},{"field":"TimeWindow","description":"Adjust for expected hours of legitimate self-enrollment"}],"live":true,"detection_strategies":["DET0036"],"techniques":["T1098.005"]},{"id":"AN0104","stix_id":"x-mitre-analytic--d5dc64ab-bb69-4893-a155-84d403040e1a","name":"Analytic 0104","description":"Adversary registers a Windows device to Entra ID or bypasses conditional access by adding device via Intune registration pipeline using stolen credentials.","url":"https://attack.mitre.org/detectionstrategies/DET0036#AN0104","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"Device Object Creation","data_component":"DC0087","data_component_name":"Active Directory Object Creation","log_source_slug":"wineventlog-security"},{"name":"ApplicationLog:Intune/MDM Logs","channel":"Enrollment events (e.g., MDMDeviceRegistration)","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"applicationlog-intune-mdm-logs"}],"mutable_elements":[{"field":"DeviceNamePattern","description":"Adjust pattern matching logic for unusual or non-corporate device names"},{"field":"UserContext","description":"Correlate with prior logon location or device usage behavior"},{"field":"EnrollmentMethod","description":"Distinguish between MDM vs manual onboarding vs automated scripts"}],"live":true,"detection_strategies":["DET0036"],"techniques":["T1098.005"]}],"live":true,"version":"1.0","techniques":["T1098.005"]}],"sigma_rules":[{"id":"a4b25073-8947-489c-a8dd-93b41c23f26d","title":"Windows LAPS Credential Dump From Entra ID","author":"andrewdanis","status":"test","level":"high","date":"2024-06-26","modified":null,"description":"Detects when an account dumps the LAPS password from Entra ID.","references":["https://twitter.com/NathanMcNulty/status/1785051227568632263","https://www.cloudcoffee.ch/microsoft-365/configure-windows-laps-in-microsoft-intune/","https://techcommunity.microsoft.com/t5/microsoft-entra-blog/introducing-windows-local-administrator-password-solution-with/ba-p/1942487"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098.005"],"path":"rules/cloud/azure/audit_logs/azure_auditlogs_laps_credential_dumping.yml","techniques":["T1098.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}