Compliance Node Overview
MITRE ATT&CK T1087.004 (Cloud Account) is an Enterprise Discovery sub-technique of T1087 (Account Discovery). Adversaries may attempt to get a listing of cloud accounts. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. With authenticated access there are several tools that can be used to find accounts. The Get-MsolRoleMember PowerShell cmdlet can be used to obtain account names given a role or permissions group in Office 365. Affected platforms: SaaS, IaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1047 Audit, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CM-06, CM-07, IA-02, IA-08.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1087/004/
SHA-256 integrity: 0de5e0e97291e176178863f8bfeba80d82c78cd0e99bd4127781b3cafdd45b63
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1087.004: Cloud Account (https://attack.mitre.org/techniques/T1087/004/)
- MITRE ATT&CK Tactic TA0007: Discovery (https://attack.mitre.org/tactics/TA0007/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access