FORENSIA

ATT&CK · T1078

Valid Accounts

Tactics: stealth, persistence, privilege-escalation, initial-access

About

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence. In some cases, adversaries may abuse inactive accounts: for example, those belonging to individuals who are no longer part of an organization. Using these accounts may allow the adversary to evade detection, as the original account user will not be present to identify any anomalous activity taking place on their account. The overlap of permissions for local, domain, and cloud accounts across a network of systems is of concern because the adversary may be able to pivot across accounts and systems to reach a high level of access (i.e., domain or enterprise administrator) to bypass access controls set within the enterprise.

Platforms: Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, WindowsMITRE ATT&CK ↗

Corpus indicators tagged with this technique

712 indicators in the corpus carry T1078.

IndicatorTypeFamilySevSrc
cve-2017-17215cve852
cve-2026-4368cveransomware851
cve-2026-22584cve852
cve-2025-66478cve852
cve-2025-68670cve852
cve-2024-1781cve851
cve-2018-8007cve851
cve-2016-0638cvephishing851
cve-2025-0921cve852
cve-2025-23304cve852
9eaa577c8ba71646928c1c34c3145536b0498f65f26060a6ba00744bcef57644sha256phishing801
6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635ahash802
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
f1551d3e5d144eef4e70a29dd3dc52fb22459d1fhash802
d78f64551d1b31a31e5998e442f0debd458e011e05019b3951d9ddde997f8384hash802
38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59sha256phishing801
78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981hashsupply_chain801
681075027553546c119ec447eb8df84633dcffcehash803
52fda5c1b9704544f32ee98d9060e689hashransomware802
873f1277a42de5c82f869459e7fb7c94554a642bhash803
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801
f4d77958a12a0778283d3e679b24b18f82e332c4hash803
b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7bsha256802
9c44bc9373377831c45dd0ac2661a28ehash803
3b6cb20891bce8602ce669187754871e402a1782031ef8b032cd007e3894bc5dhash802
6a69ea2ce3fea0ebfd7a32a1dfc4251bd4d7d8a4fbd44aaa47b82290d0414a9fhash802
2654c08491a0f7c4a3dfc6282de5638bhash803
01e3dce00ea45829bd9f6a583004976ac63973a0hashcryptojacking801
123e80a34508c4dede7cc70e76931fcchash803
686213cc11d36af764de824801bced9366dfca3823fe0d51b752f74149bcf1f4sha256ransomware801

Showing the top 30 by severity of 712.