Compliance Node Overview
MITRE ATT&CK T1078.004 covers adversary use of legitimate cloud account credentials (Microsoft Entra ID / Azure AD, AWS IAM, Google Workspace, GCP, Okta, Salesforce) to gain initial access, maintain persistence, escalate privileges, and evade detection. Cloud account abuse is the dominant attack pattern in modern SaaS-heavy environments: SCATTERED SPIDER, Storm-0558, MUDDLED LIBRA, and most major 2023-2024 breaches involved cloud credential compromise. Compliance obligations include NIST SP 800-53 IA-2, AC-2, AC-6, ISO 27001 A.5.16-A.5.18, A.8.2, PCI DSS Req 8, HIPAA 164.308(a)(4), DORA Article 9, NIS2 Article 21(2)(j), and CISA Cloud Security Technical Reference Architecture.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1078/004/
SHA-256 integrity: 126fd698b804f37ac24ce1623e5317209f881269dfda126f1e5af6520b918504
Primary Citations — 8 traced to source
- MITRE ATT&CK Technique T1078.004: Cloud Accounts (https://attack.mitre.org/techniques/T1078/004/)
- NIST SP 800-53 Rev 5: IA-2 (Identification and Authentication), AC-2 (Account Management)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access