Compliance Node Overview
MITRE ATT&CK T1098.003 (Additional Cloud Roles) is an Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permissions, a compromised account can gain almost unlimited access to data and settings (including the ability to reset the passwords of other admins). Affected platforms: IaaS, SaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1026 Privileged Account Management, M1032 Multi-factor Authentication, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-20, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1098/003/
SHA-256 integrity: fb58e9cf60db75e2305e3f3fc4931a530e0bdd30cafbc136b968349037785ae9
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1098.003: Additional Cloud Roles (https://attack.mitre.org/techniques/T1098/003/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access