Sub-technique of T1078 Valid Accounts.View on attack.mitre.org
Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.
Adversaries may compromise domain accounts, some with a high level of privileges, through various means such as OS Credential Dumping or password reuse, allowing access to privileged resources of the domain.
Rules on DetectionCode tagged with T1078.002.
| Rule | Level | Log source |
|---|---|---|
| Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure | high | aws / NULL |
| DMSA Service Account Created in Specific OUs - PowerShell | medium | windows / ps_script |
| New DMSA Service Account Created in Specific OUs | medium | windows / process_creation |
| Admin User Remote Logon | low | windows / NULL |
| DMSA Link Attributes Modified | low | windows / ps_script |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect Excessive Account Lockouts From Endpoint | Anomaly | NULL | |
| Identify New User Accounts | Hunting | NULL | |
| Suspicious Computer Account Name Change | TTP | NULL | Windows Event Log Security 4781 |
| Suspicious Kerberos Service Ticket Request | TTP | NULL | Windows Event Log Security 4769 |
| Suspicious Ticket Granting Ticket Request | Hunting | NULL | Windows Event Log Security 4768, Windows Event Log Security 4781 |
| Windows AD User Suspicious UPN Change | TTP | NULL | Windows Event Log Security 4738 |
| Windows Group Policy Object Created | TTP | NULL | Windows Event Log Security 5136, Windows Event Log Security 5137 |
| Windows PowerView AD Access Control List Enumeration | TTP | NULL | Powershell Script Block Logging 4104 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement. |
| GroupAPT3 | APT3 leverages valid accounts after gaining credentials for use within the victim domain. |
| GroupAPT5 | APT5 has used legitimate account credentials to move laterally through compromised environments. |
| GroupAquatic Panda | Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments. |
| GroupBlackByte | BlackByte captured credentials for or impersonated domain administration users. |
| GroupChimera | Chimera has used compromised domain accounts to gain access to the target environment. |
| GroupCinnamon Tempest | Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware. |
| GroupIndrik Spider | Indrik Spider has collected credentials from infected systems, including domain accounts. |
| Used by | Procedure example |
|---|---|
| MalwareCobalt Strike | Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account. |
| MalwareCreepySnail | CreepySnail can use stolen credentials to authenticate on target networks. |
| MalwareRyuk | Ryuk can use stolen domain admin accounts to move laterally within a victim domain. |
| MalwareShamoon | If Shamoon cannot access shares using current privileges, it attempts access using hard coded, domain-specific credentials gathered earlier in the intrusion. |
| MalwareStuxnet | Stuxnet attempts to access network resources with a domain account’s credentials. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, threat actors utilized privileged accounts to access the FortiGate VPN solution and subsequent subnets. |
| CampaignCutting Edge | During Cutting Edge, threat actors used compromised VPN accounts for lateral movement on targeted networks. |
| CampaignLeviathan Australian Intrusions | Leviathan compromised domain credentials during Leviathan Australian Intrusions. |
| CampaignNight Dragon | During Night Dragon, threat actors used domain accounts to gain further access to victim systems. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used compromised domain administrator credentials as part of their lateral movement. |
| CampaignOperation Ghost | For Operation Ghost, APT29 used stolen administrator credentials for lateral movement on compromised networks. |
| CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used domain credentials, including domain admin, for lateral movement and privilege escalation. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.