Compliance Node Overview
MITRE ATT&CK T1078.002 (Domain Accounts) is an Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1018 User Account Management, M1032 Multi-factor Authentication, M1026 Privileged Account Management, M1017 User Training, M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-07, AC-20, CA-03, CA-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1078/002/
SHA-256 integrity: 4f13cb0baf26a35381bfc9238ccfd4d54bff9cb18da4cf748c27ebfd93d4d828
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1078.002: Domain Accounts (https://attack.mitre.org/techniques/T1078/002/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access