Compliance Node Overview
MITRE ATT&CK T1021.007 (Cloud Services) is an Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may log into accessible cloud services within a compromised environment using Valid Accounts that are synchronized with or federated to on-premises user identities. The adversary may then perform management actions or access cloud-hosted resources as the logged-on user. Many enterprises federate centrally managed user identities to cloud services, allowing users to login with their domain credentials in order to access the cloud control plane. Affected platforms: SaaS, IaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-07, AC-17, AC-20, CM-02.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1021/007/
SHA-256 integrity: 4906ad879b5fe1a2a4a4d1012fb0ecd4ecd8dc56b8d104f90fbc6caf4f349e13
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1021.007: Cloud Services (https://attack.mitre.org/techniques/T1021/007/)
- MITRE ATT&CK Tactic TA0008: Lateral Movement (https://attack.mitre.org/tactics/TA0008/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access