{"id":"T1098","name":"Account Manipulation","url":"https://attack.mitre.org/techniques/T1098","tactics":["persistence","privilege-escalation"],"platforms":["Containers","ESXi","IaaS","Identity Provider","Linux","macOS","Network Devices","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0096","stix_id":"x-mitre-detection-strategy--d6c4cc3b-6875-4288-8193-bf4c864560ab","name":"Account Manipulation Behavior Chain Detection","url":"https://attack.mitre.org/detectionstrategies/DET0096","analytics":[{"id":"AN0265","stix_id":"x-mitre-analytic--842ba5ee-dcd0-42bd-9ef8-867a4ab1c703","name":"Analytic 0265","description":"Account attribute changes (e.g., password set, group membership, servicePrincipalName, logon hours) correlated with unusual process lineage or timing, indicating privilege escalation or persistence via valid accounts.","url":"https://attack.mitre.org/detectionstrategies/DET0096#AN0265","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4738, 4728, 4670","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Time between suspicious process and account change (e.g., 5m)."},{"field":"HighPrivilegeGroupList","description":"Customize group list (e.g., Domain Admins, Enterprise Admins) to monitor."},{"field":"SubjectTargetMismatch","description":"Flag if account modifier != modified user (potential hijack)."}],"live":true,"detection_strategies":["DET0096"],"techniques":["T1098"]},{"id":"AN0266","stix_id":"x-mitre-analytic--0eb6cf59-4ba8-4cea-b64a-686ce7c69f70","name":"Analytic 0266","description":"Use of native tools or scripting (e.g., `usermod`, `passwd`, `groupmod`) to escalate permissions or persist access on existing users, correlated with login or process events.","url":"https://attack.mitre.org/detectionstrategies/DET0096#AN0266","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"usermod, groupmod, passwd","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:PATH","channel":"/etc/passwd or /etc/group file write","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-path"}],"mutable_elements":[{"field":"SudoPath","description":"Common sudo or privilege escalation paths (e.g., `/usr/bin/passwd`)."},{"field":"ModifiedShellList","description":"Detect if user shell is changed to unusual one (e.g., /bin/sh -> /bin/bash)."}],"live":true,"detection_strategies":["DET0096"],"techniques":["T1098"]},{"id":"AN0267","stix_id":"x-mitre-analytic--616ccbf4-08f2-4b54-8e41-a8e362e31827","name":"Analytic 0267","description":"Modifications to user accounts via `dscl`, `pwpolicy`, or System Preferences CLI (`sysadminctl`) that alter user groups, enable root, or bypass MDM restrictions.","url":"https://attack.mitre.org/detectionstrategies/DET0096#AN0267","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"com.apple.accountsd, com.apple.opendirectoryd","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ModifiedUserList","description":"Track known non-system user UIDs or service accounts."},{"field":"GroupMembershipChanges","description":"List of sensitive groups (admin, _developer, _analyticsd)."}],"live":true,"detection_strategies":["DET0096"],"techniques":["T1098"]},{"id":"AN0268","stix_id":"x-mitre-analytic--5c69f3b9-8f73-455e-8eb1-5281cd6ce6d5","name":"Analytic 0268","description":"Modifications to SSO/SAML user attributes (e.g., `isAdmin`, `role`, MFA bypass, App assignments) often through CLI, API, or rogue IdP apps.","url":"https://attack.mitre.org/detectionstrategies/DET0096#AN0268","platforms":["Identity Provider"],"log_source_references":[{"name":"saas:okta","channel":"User Attribute Modified / Role Assignment Changed","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"saas-okta"}],"mutable_elements":[{"field":"RoleAssignmentBaseline","description":"Expected user-role pairings per app or org unit."},{"field":"APIUsageContext","description":"Caller identity or IP address ranges for identity admin actions."}],"live":true,"detection_strategies":["DET0096"],"techniques":["T1098"]},{"id":"AN0269","stix_id":"x-mitre-analytic--74565d24-df58-49b6-86e0-01a03d6dc2a7","name":"Analytic 0269","description":"Addition of new users or changes to role permissions (e.g., ReadOnly -> Admin) via API or vSphere Client, particularly from non-jumpbox IPs.","url":"https://attack.mitre.org/detectionstrategies/DET0096#AN0269","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vpxa","channel":"vim.SessionManager.login / vim.AccountManager.createUser","data_component":"DC0066","data_component_name":"Active Directory Object Modification","log_source_slug":"esxi-vpxa"}],"mutable_elements":[{"field":"VMAdminAccountName","description":"Expected account name patterns for ESXi/vCenter admins."},{"field":"NetworkAccessLocation","description":"Expected IPs/subnets for legitimate ESXi access."}],"live":true,"detection_strategies":["DET0096"],"techniques":["T1098"]},{"id":"AN0270","stix_id":"x-mitre-analytic--eb4a55f0-eff2-40f8-912e-43ba7e34603c","name":"Analytic 0270","description":"Role escalation (e.g., Editor → Owner) in cloud collaboration tools (Google Workspace, O365) or file sharing apps to maintain elevated access.","url":"https://attack.mitre.org/detectionstrategies/DET0096#AN0270","platforms":["SaaS"],"log_source_references":[{"name":"m365:unified","channel":"Admin Activity > Role Change or Sharing Change","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"SharingSensitivityLabel","description":"Threshold for labeling sensitive document access escalation."},{"field":"CrossOrgChanges","description":"Track changes made across organizational boundaries (e.g., guest users)."}],"live":true,"detection_strategies":["DET0096"],"techniques":["T1098"]}],"live":true,"version":"1.0","techniques":["T1098"]}],"sigma_rules":[{"id":"02122374-b74e-495c-b285-9e4da973f3d6","title":"DMSA Service Account Created in Specific OUs - PowerShell","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-05-24","modified":null,"description":"Detects the creation of a dMSA service account using the New-ADServiceAccount cmdlet in certain OUs.\nThe fact that the cmdlet is used to create a dMSASvc account in a specific OU is highly suspicious.\nIt is a pattern trying to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025.\nOn top of that, if the user that is creating the dMSASvc account is not a legitimate administrator or does not have the necessary permissions,\nit is a strong signal of an attempted or successful abuse of the BaDSuccessor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.\n","references":["https://www.akamai.com/blog/security-research/abusing-bad-successor-for-privilege-escalation-in-active-directory"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.privilege-escalation","attack.initial-access","attack.persistence","attack.stealth","attack.t1078.002","attack.t1098"],"path":"rules/windows/powershell/powershell_script/posh_ps_create_new_dmsasvc_account.yml","techniques":["T1078.002","T1098"],"cves":[]},{"id":"0255a820-e564-4e40-af2b-6ac61160335c","title":"A New Trust Was Created To A Domain","author":"Thomas Patzke","status":"stable","level":"medium","date":"2019-12-03","modified":"2024-01-16","description":"Addition of domains is seldom and should be verified for legitimacy.","references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4706"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/windows/builtin/security/win_security_susp_add_domain_trust.yml","techniques":["T1098"],"cves":[]},{"id":"02c39d30-02b5-45d2-b435-8aebfe5a8629","title":"A Member Was Removed From a Security-Enabled Global Group","author":"Alexandr Yampolskyi, SOC Prime","status":"stable","level":"low","date":"2023-04-26","modified":null,"description":"Detects activity when a member is removed from a security-enabled global group","references":["https://www.cisecurity.org/controls/cis-controls-list/","https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf","https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4729","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=633"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/windows/builtin/security/account_management/win_security_member_removed_security_enabled_global_group.yml","techniques":["T1098"],"cves":[]},{"id":"04e2a23a-9b29-4a5c-be3a-3542e3f982ba","title":"Google Workspace Granted Domain API Access","author":"Austin Songer","status":"test","level":"medium","date":"2021-08-23","modified":"2023-10-11","description":"Detects when an API access service account is granted domain authority.","references":["https://cloud.google.com/logging/docs/audit/gsuite-audit-logging#3","https://developers.google.com/admin-sdk/reports/v1/appendix/activity/admin-domain-settings#AUTHORIZE_API_CLIENT_ACCESS"],"logsource":{"product":"gcp","service":"google_workspace.admin"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/cloud/gcp/gworkspace/admin/gcp_gworkspace_granted_domain_api_access.yml","techniques":["T1098"],"cves":[]},{"id":"055fb148-60f8-462d-ad16-26926ce050f1","title":"AWS User Login Profile Was Modified","author":"toffeebr33k","status":"test","level":"high","date":"2021-08-09","modified":"2024-04-26","description":"Detects activity when someone is changing passwords on behalf of other users.\nAn attacker with the \"iam:UpdateLoginProfile\" permission on other users can change the password used to login to the AWS console on any user that already has a login profile setup.\n","references":["https://github.com/RhinoSecurityLabs/AWS-IAM-Privilege-Escalation"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1098"],"path":"rules/cloud/aws/cloudtrail/aws_update_login_profile.yml","techniques":["T1098"],"cves":[]},{"id":"0a5177f4-6ca9-44c2-aacf-d3f3d8b6e4d2","title":"AWS IAM Backdoor Users Keys","author":"faloker","status":"test","level":"medium","date":"2020-02-12","modified":"2022-10-09","description":"Detects AWS API key creation for a user by another user.\nBackdoored users can be used to obtain persistence in the AWS environment.\nAlso with this alert, you can detect a flow of AWS keys in your org.\n","references":["https://github.com/RhinoSecurityLabs/pacu/blob/866376cd711666c775bbfcde0524c817f2c5b181/pacu/modules/iam__backdoor_users_keys/main.py"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1098"],"path":"rules/cloud/aws/cloudtrail/aws_iam_backdoor_users_keys.yml","techniques":["T1098"],"cves":[]},{"id":"0ac15ec3-d24f-4246-aa2a-3077bb1cf90e","title":"Privileged User Has Been Created","author":"Pawel Mazur","status":"test","level":"high","date":"2022-12-21","modified":"2025-01-21","description":"Detects the addition of a new user to a privileged group such as \"root\" or \"sudo\"","references":["https://digital.nhs.uk/cyber-alerts/2018/cc-2825","https://linux.die.net/man/8/useradd","https://github.com/redcanaryco/atomic-red-team/blob/25acadc0b43a07125a8a5b599b28bbc1a91ffb06/atomics/T1136.001/T1136.001.md#atomic-test-5---create-a-new-user-in-linux-with-root-uid-and-gid"],"logsource":{"product":"linux"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1136.001","attack.t1098"],"path":"rules/linux/builtin/lnx_privileged_user_creation.yml","techniques":["T1136.001","T1098"],"cves":[]},{"id":"0ea8db81-2ff6-4525-9448-33bbe7effc13","title":"New DMSA Service Account Created in Specific OUs","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-05-24","modified":null,"description":"Detects the creation of a dMSASvc account using the New-ADServiceAccount cmdlet in certain OUs.\nThe fact that the Cmdlet is used to create a dMSASvc account in a specific OU is highly suspicious.\nIt is a pattern trying to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025.\nOn top of that, if the user that is creating the dMSASvc account is not a legitimate administrator or does not have the necessary permissions,\nit is a strong signal of an attempted or successful abuse of the BaDSuccessor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.\n","references":["https://www.akamai.com/blog/security-research/abusing-bad-successor-for-privilege-escalation-in-active-directory"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.initial-access","attack.persistence","attack.stealth","attack.t1078.002","attack.t1098"],"path":"rules/windows/process_creation/proc_creation_win_create_new_dmsasvc_account.yml","techniques":["T1078.002","T1098"],"cves":[]},{"id":"102e11e3-2db5-4c9e-bc26-357d42585d21","title":"Bulk Deletion Changes To Privileged Account Permissions","author":"Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H'","status":"test","level":"high","date":"2022-08-05","modified":null,"description":"Detects when a user is removed from a privileged role. Bulk changes should be investigated.","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-identity-management#azure-ad-roles-assignment"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/cloud/azure/audit_logs/azure_priviledged_role_assignment_bulk_change.yml","techniques":["T1098"],"cves":[]},{"id":"10fb649c-3600-4d37-b1e6-56ea90bb7e09","title":"User Added To Highly Privileged Group","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2024-02-23","modified":null,"description":"Detects addition of users to highly privileged groups via \"Net\" or \"Add-LocalGroupMember\".","references":["https://www.huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/windows/process_creation/proc_creation_win_susp_add_user_privileged_group.yml","techniques":["T1098"],"cves":[]},{"id":"258b6593-215d-4a26-a141-c8e31c1299a6","title":"Anomalous User Activity","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-03","modified":null,"description":"Indicates that there are anomalous patterns of behavior like suspicious changes to the directory.","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#anomalous-user-activity","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.privilege-escalation","attack.t1098","attack.persistence"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_anomalous_user.yml","techniques":["T1098"],"cves":[]},{"id":"2c99737c-585d-4431-b61a-c911d86ff32f","title":"Powerview Add-DomainObjectAcl DCSync AD Extend Right","author":"Samir Bousseaden, Roberto Rodriguez @Cyb3rWard0g, oscd.community, Tim Shelton, Maxence Fossat","status":"test","level":"high","date":"2019-04-03","modified":"2022-08-16","description":"Backdooring domain object to grant the rights associated with DCSync to a regular user or machine account using Powerview\\Add-DomainObjectAcl DCSync Extended Right cmdlet, will allow to re-obtain the pwd hashes of any user/computer","references":["https://twitter.com/menasec1/status/1111556090137903104","https://www.specterops.io/assets/resources/an_ace_up_the_sleeve.pdf"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/windows/builtin/security/win_security_account_backdoor_dcsync_rights.yml","techniques":["T1098"],"cves":[]},{"id":"2d1b83e4-17c6-4896-a37b-29140b40a788","title":"Google Workspace User Granted Admin Privileges","author":"Austin Songer","status":"test","level":"medium","date":"2021-08-23","modified":"2023-10-11","description":"Detects when an Google Workspace user is granted admin privileges.","references":["https://cloud.google.com/logging/docs/audit/gsuite-audit-logging#3","https://developers.google.com/admin-sdk/reports/v1/appendix/activity/admin-user-settings#GRANT_ADMIN_PRIVILEGE"],"logsource":{"product":"gcp","service":"google_workspace.admin"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/cloud/gcp/gworkspace/admin/gcp_gworkspace_user_granted_admin_privileges.yml","techniques":["T1098"],"cves":[]},{"id":"300bac00-e041-4ee2-9c36-e262656a6ecc","title":"Active Directory User Backdoors","author":"@neu5ron","status":"test","level":"high","date":"2017-04-13","modified":"2024-02-26","description":"Detects scenarios where one can control another users or computers account without having to use their credentials.","references":["https://msdn.microsoft.com/en-us/library/cc220234.aspx","https://adsecurity.org/?p=3466","https://blog.harmj0y.net/redteaming/another-word-on-delegation/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.t1098","attack.persistence"],"path":"rules/windows/builtin/security/win_security_alert_ad_user_backdoors.yml","techniques":["T1098"],"cves":[]},{"id":"311b6ce2-7890-4383-a8c2-663a9f6b43cd","title":"Enabled User Right in AD to Control User Objects","author":"@neu5ron","status":"test","level":"high","date":"2017-07-30","modified":"2021-12-02","description":"Detects scenario where if a user is assigned the SeEnableDelegationPrivilege right in Active Directory it would allow control of other AD user objects.","references":["https://blog.harmj0y.net/activedirectory/the-most-dangerous-user-right-you-probably-have-never-heard-of/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/windows/builtin/security/win_security_alert_active_directory_user_control.yml","techniques":["T1098"],"cves":[]},{"id":"32438676-1dba-4ac7-bf69-b86cba995e05","title":"GCP Access Policy Deleted","author":"Bryan Lim","status":"test","level":"medium","date":"2024-01-12","modified":null,"description":"Detects when an access policy that is applied to a GCP cloud resource is deleted.\nAn adversary would be able to remove access policies to gain access to a GCP cloud resource.\n","references":["https://cloud.google.com/access-context-manager/docs/audit-logging","https://cloud.google.com/logging/docs/audit/understanding-audit-logs","https://cloud.google.com/logging/docs/reference/audit/auditlog/rest/Shared.Types/AuditLog"],"logsource":{"product":"gcp","service":"gcp.audit"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1098"],"path":"rules/cloud/gcp/audit/gcp_access_policy_deleted.yml","techniques":["T1098"],"cves":[]},{"id":"3940b5f1-3f46-44aa-b746-ebe615b879e0","title":"AWS Route 53 Domain Transfer Lock Disabled","author":"Elastic, Austin Songer @austinsonger","status":"test","level":"low","date":"2021-07-22","modified":"2022-10-09","description":"Detects when a transfer lock was removed from a Route 53 domain. It is recommended to refrain from performing this action unless intending to transfer the domain to a different registrar.","references":["https://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/integrations/aws/persistence_route_53_domain_transfer_lock_disabled.toml","https://docs.aws.amazon.com/Route53/latest/APIReference/API_Operations_Amazon_Route_53.html","https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_DisableDomainTransferLock.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.persistence","attack.privilege-escalation","attack.credential-access","attack.t1098"],"path":"rules/cloud/aws/cloudtrail/aws_route_53_domain_transferred_lock_disabled.yml","techniques":["T1098"],"cves":[]},{"id":"45eb2ae2-9aa2-4c3a-99a5-6e5077655466","title":"Suspicious Computer Account Name Change CVE-2021-42287","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-12-22","modified":"2022-12-25","description":"Detects the renaming of an existing computer account to a account name that doesn't contain a $ symbol as seen in attacks against CVE-2021-42287","references":["https://medium.com/@mvelazco/hunting-for-samaccountname-spoofing-cve-2021-42287-and-domain-controller-impersonation-f704513c8a45"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.stealth","attack.t1036","attack.t1098","cve.2021-42287","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-42287/win_security_samaccountname_spoofing_cve_2021_42287.yml","techniques":["T1036","T1098"],"cves":["CVE-2021-42287"]},{"id":"4d78a000-ab52-4564-88a5-7ab5242b20c7","title":"Change to Authentication Method","author":"AlertIQ","status":"test","level":"medium","date":"2021-10-10","modified":"2022-12-25","description":"Change to authentication method could be an indicator of an attacker adding an auth method to the account so they can have continued access.","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-accounts"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.privilege-escalation","attack.credential-access","attack.defense-impairment","attack.t1556","attack.persistence","attack.t1098"],"path":"rules/cloud/azure/audit_logs/azure_change_to_authentication_method.yml","techniques":["T1556","T1098"],"cves":[]},{"id":"4fdc44df-bfe9-4fcc-b041-68f5a2d3031c","title":"Powershell LocalAccount Manipulation","author":"frack113","status":"test","level":"medium","date":"2021-12-28","modified":null,"description":"Adversaries may manipulate accounts to maintain access to victim systems.\nAccount manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1098/T1098.md#atomic-test-1---admin-account-manipulate","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.localaccounts/?view=powershell-5.1"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/windows/powershell/powershell_script/posh_ps_localuser.yml","techniques":["T1098"],"cves":[]},{"id":"53ad8e36-f573-46bf-97e4-15ba5bf4bb51","title":"Password Change on Directory Service Restore Mode (DSRM) Account","author":"Thomas Patzke","status":"stable","level":"high","date":"2017-02-19","modified":"2020-08-23","description":"Detects potential attempts made to set the Directory Services Restore Mode administrator password.\nThe Directory Service Restore Mode (DSRM) account is a local administrator account on Domain Controllers.\nAttackers may change the password in order to obtain persistence.\n","references":["https://adsecurity.org/?p=1714","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4794"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/windows/builtin/security/win_security_susp_dsrm_password_change.yml","techniques":["T1098"],"cves":[]},{"id":"6c9eb492-e477-4df9-b0f4-571fc9db29cd","title":"msDS-ManagedAccountPrecededByLink Attribute Modified","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-05-24","modified":null,"description":"Detects modifications to the msDS-ManagedAccountPrecededByLink attribute, which may indicate an attempted or successful abuse of the BaD-Successor msDS-DelegatedManagedServiceAccount (DMSA) vulnerability.\nThe DMSA is a new object class introduced in Windows Server 2025 that allows administrators to delegate the management of service accounts to other users or groups.\nChanges to this attribute by suspicious accounts or outside of normal administrative workflows are a strong signal of an attempted or successful abuse.\nIf it is indeed modified by an account that is not typically responsible for such changes, it could indicate an attempt to exploit the BaD-Successor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.\n","references":["https://www.akamai.com/blog/security-research/abusing-bad-successor-for-privilege-escalation-in-active-directory"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.initial-access","attack.persistence","attack.stealth","attack.t1078.002","attack.t1098"],"path":"rules-placeholder/windows/builtin/security/win_security_modification_of_msds_dmsa_link_attribute.yml","techniques":["T1078.002","T1098"],"cves":[]},{"id":"6d844f0f-1c18-41af-8f19-33e7654edfc3","title":"Cisco Local Accounts","author":"Austin Clark","status":"test","level":"high","date":"2019-08-12","modified":"2023-01-04","description":"Find local accounts being created or modified as well as remote authentication configurations","references":[],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1136.001","attack.t1098"],"path":"rules/network/cisco/aaa/cisco_cli_local_accounts.yml","techniques":["T1136.001","T1098"],"cves":[]},{"id":"7864a175-3654-4824-9f0d-f0da18ab27c0","title":"Password Set to Never Expire via WMI","author":"Daniel Koifman (KoifSec)","status":"experimental","level":"medium","date":"2025-07-30","modified":null,"description":"Detects the use of wmic.exe to modify user account settings and explicitly disable password expiration.\n","references":["https://www.huntress.com/blog/the-unwanted-guest"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.t1047","attack.t1098"],"path":"rules/windows/process_creation/proc_creation_win_wmi_password_never_expire.yml","techniques":["T1047","T1098"],"cves":[]},{"id":"9691f58d-92c1-4416-8bf3-2edd753ec9cf","title":"ESXi Admin Permission Assigned To Account Via ESXCLI","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-09-04","modified":null,"description":"Detects execution of the \"esxcli\" command with the \"system\" and \"permission\" flags in order to assign admin permissions to an account.","references":["https://developer.broadcom.com/xapis/esxcli-command-reference/7.0.0/namespace/esxcli_system.html"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.persistence","attack.execution","attack.privilege-escalation","attack.t1059.012","attack.t1098"],"path":"rules/linux/process_creation/proc_creation_lnx_esxcli_permission_change_admin.yml","techniques":["T1059.012","T1098"],"cves":[]},{"id":"9b111d8e-92e0-4153-88bc-daefc1333aba","title":"DMSA Link Attributes Modified","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"low","date":"2025-05-24","modified":null,"description":"Detects modification of dMSA link attributes (msDS-ManagedAccountPrecededByLink) via PowerShell scripts.\nThis command line pattern could be an indicator an attempt to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025.\n","references":["https://www.akamai.com/blog/security-research/abusing-bad-successor-for-privilege-escalation-in-active-directory"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078.002","attack.t1098"],"path":"rules/windows/powershell/powershell_script/posh_ps_modification_of_dmsa_link_attribute.yml","techniques":["T1078.002","T1098"],"cves":[]},{"id":"aac6c4f4-87c7-4961-96ac-c3fd3a42c310","title":"Bitbucket Global Permission Changed","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"medium","date":"2024-02-25","modified":null,"description":"Detects global permissions change activity.","references":["https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html","https://confluence.atlassian.com/bitbucketserver/global-permissions-776640369.html"],"logsource":{"product":"bitbucket","service":"audit"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1098"],"path":"rules/application/bitbucket/audit/bitbucket_audit_global_permissions_change_detected.yml","techniques":["T1098"],"cves":[]},{"id":"ad720b90-25ad-43ff-9b5e-5c841facc8e5","title":"User Added to Local Administrators Group","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-08-12","modified":"2023-03-02","description":"Detects addition of users to the local administrator group via \"Net\" or \"Add-LocalGroupMember\".","references":["https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html?m=1"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/windows/process_creation/proc_creation_win_susp_add_user_local_admin_group.yml","techniques":["T1098"],"cves":[]},{"id":"b056de1a-6e6e-4e40-a67e-97c9808cf41b","title":"AWS Route 53 Domain Transferred to Another Account","author":"Elastic, Austin Songer @austinsonger","status":"test","level":"low","date":"2021-07-22","modified":"2022-10-09","description":"Detects when a request has been made to transfer a Route 53 domain to another AWS account.","references":["https://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/integrations/aws/persistence_route_53_domain_transferred_to_another_account.toml"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.persistence","attack.credential-access","attack.privilege-escalation","attack.t1098"],"path":"rules/cloud/aws/cloudtrail/aws_route_53_domain_transferred_to_another_account.yml","techniques":["T1098"],"cves":[]},{"id":"b237c54b-0f15-4612-a819-44b735e0de27","title":"A Security-Enabled Global Group Was Deleted","author":"Alexandr Yampolskyi, SOC Prime","status":"stable","level":"low","date":"2023-04-26","modified":null,"description":"Detects activity when a security-enabled global group is deleted","references":["https://www.cisecurity.org/controls/cis-controls-list/","https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf","https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4730","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=634"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/windows/builtin/security/account_management/win_security_security_enabled_global_group_deleted.yml","techniques":["T1098"],"cves":[]},{"id":"c265cf08-3f99-46c1-8d59-328247057d57","title":"User Added to Local Administrator Group","author":"Florian Roth (Nextron Systems)","status":"stable","level":"medium","date":"2017-03-14","modified":"2021-01-17","description":"Detects the addition of a new member to the local administrator group, which could be legitimate activity or a sign of privilege escalation activity","references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4732","https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-identifiers"],"logsource":{"product":"windows","service":"security"},"tags":["attack.initial-access","attack.privilege-escalation","attack.stealth","attack.t1078","attack.persistence","attack.t1098"],"path":"rules/windows/builtin/security/win_security_user_added_to_local_administrators.yml","techniques":["T1078","T1098"],"cves":[]},{"id":"c43c26be-2e87-46c7-8661-284588c5a53e","title":"A Member Was Added to a Security-Enabled Global Group","author":"Alexandr Yampolskyi, SOC Prime","status":"stable","level":"low","date":"2023-04-26","modified":null,"description":"Detects activity when a member is added to a security-enabled global group","references":["https://www.cisecurity.org/controls/cis-controls-list/","https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf","https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4728","https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=632"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/windows/builtin/security/account_management/win_security_member_added_security_enabled_global_group.yml","techniques":["T1098"],"cves":[]},{"id":"d2d901db-7a75-45a1-bc39-0cbf00812192","title":"Number Of Resource Creation Or Deployment Activities","author":"sawwinnnaung","status":"test","level":"medium","date":"2020-05-07","modified":"2023-10-11","description":"Number of VM creations or deployment activities occur in Azure via the azureactivity log.","references":["https://github.com/Azure/Azure-Sentinel/blob/e534407884b1ec5371efc9f76ead282176c9e8bb/Detections/AzureActivity/Creating_Anomalous_Number_Of_Resources_detection.yaml"],"logsource":{"product":"azure","service":"activitylogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1098"],"path":"rules/cloud/azure/activity_logs/azure_creating_number_of_resources_detection.yml","techniques":["T1098"],"cves":[]},{"id":"e15bc294-ae2a-45ad-b7d6-637b33868bde","title":"New MsDS-DelegatedManagedServiceAccount (DMSA) Object Created","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-05-24","modified":null,"description":"Detects the creation of new msDS-DelegatedManagedServiceAccount objects, which could indicate potential abuse of privilege escalation vulnerabilities in Windows Server 2025.\nThe msDS-DelegatedManagedServiceAccount (DMSA) is a new object class introduced in Windows Server 2025 that allows administrators to delegate the management of service accounts to other users or groups.\nAttackers may exploit this feature to create unauthorized service accounts with elevated privileges, leading to privilege escalation within the Active Directory environment.\nIt is highly suspicious if an msDS-DelegatedManagedServiceAccount object is created without proper authorization or in an unexpected context, such as by a non-administrative user or outside of normal administrative workflows.\nSo, it's a good idea to look out for accounts that are not typically responsible for service account creation to detect potential abuse of this feature.\n","references":["https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.initial-access","attack.persistence","attack.stealth","attack.t1078.002","attack.t1098"],"path":"rules-placeholder/windows/builtin/security/win_security_msds_dmsa_object_creation.yml","techniques":["T1078.002","T1098"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2021-32030","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2012-0767","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}