Compliance Node Overview
MITRE ATT&CK T1136.003 (Cloud Account) is an Enterprise Persistence sub-technique of T1136 (Create Account). Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system. In addition to user accounts, cloud accounts may be associated with services. Cloud providers handle the concept of service accounts in different ways. Affected platforms: IaaS, SaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1030 Network Segmentation, M1032 Multi-factor Authentication, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-20, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1136/003/
SHA-256 integrity: 06ed00fca123961235a7a375d7a75de6aaadda140e472a8bc464b19acad2140b
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1136.003: Cloud Account (https://attack.mitre.org/techniques/T1136/003/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access