{"id":"T1585.003","name":"Cloud Accounts","url":"https://attack.mitre.org/techniques/T1585/003","tactics":["resource-development"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0846","stix_id":"x-mitre-detection-strategy--1f7b4b6e-17ab-446f-ac4e-5a1e79569dd3","name":"Detection of Cloud Accounts","url":"https://attack.mitre.org/detectionstrategies/DET0846","analytics":[{"id":"AN1978","stix_id":"x-mitre-analytic--97ec7ade-18b7-43b7-b267-85470862b6ac","name":"Analytic 1978","description":"Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during exfiltration (ex: [Transfer Data to Cloud Account](https://attack.mitre.org/techniques/T1537)).","url":"https://attack.mitre.org/detectionstrategies/DET0846#AN1978","platforms":["PRE"],"log_source_references":[],"mutable_elements":[],"live":true,"detection_strategies":["DET0846"],"techniques":["T1585.003"]}],"live":true,"version":"1.0","techniques":["T1585.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}