ATT&CK · T1087.004 · sub-technique
Cloud Account
Tactics: discovery
About
Adversaries may attempt to get a listing of cloud accounts. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. With authenticated access there are several tools that can be used to find accounts. The <code>Get-MsolRoleMember</code> PowerShell cmdlet can be used to obtain account names given a role or permissions group in Office 365. The Azure CLI (AZ CLI) also provides an interface to obtain user accounts with authenticated access to a domain. The command <code>az ad user list</code> will list all users within a domain. The AWS command <code>aws iam list-users</code> may be used to obtain a list of users in the current account while <code>aws iam list-roles</code> can obtain IAM roles that have a specified path prefix. In GCP, <code>gcloud iam service-accounts list</code> and <code>gcloud projects get-iam-policy</code> may be used to obtain a listing of service accounts and users in a project.
Used by actors
2 known groups
Software
3 malware/tools implement this
Corpus indicators tagged with this technique
7 indicators in the corpus carry T1087.004.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| 7d80b3ef74ad7992b93c31966962612e4e2ceb93e7727cdbd1d2a9af47d44ba8 | hash | supply_chain | 80 | 1 |
| 069ac1dc7f7649b76bc72a11ac700f373804bfd81dab7e561157b703999f44ce | hash | supply_chain | 80 | 1 |
| 877ff2531a63393c4cb9c3c86908b62d9c4fc3db971bc231c48537faae6cb3ec | hash | supply_chain | 80 | 1 |
| aeaf583e20347bf850e2fabdcd6f4982996ba023f8c2cd56bbd299cfd56516f5 | hash | supply_chain | 80 | 1 |
| https://t.m-kosche.com/rope.pyz | url | supply_chain | 75 | 1 |
| https://check.git-service.com/rope.pyz | url | supply_chain | 75 | 1 |
| 138.226.246.94 | ip | supply_chain | 70 | 5 |