Domain Accounts

T1078.002

Sub-technique of T1078 Valid Accounts.View on attack.mitre.org

About this technique

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Adversaries may compromise domain accounts, some with a high level of privileges, through various means such as OS Credential Dumping or password reuse, allowing access to privileged resources of the domain.

Detection rules13

Rules on DetectionCode tagged with T1078.002.

Sigma5

Splunk8

RuleTypeRiskData source
Detect Excessive Account Lockouts From EndpointAnomalyNULL
Identify New User AccountsHuntingNULL
Suspicious Computer Account Name ChangeTTPNULLWindows Event Log Security 4781
Suspicious Kerberos Service Ticket RequestTTPNULLWindows Event Log Security 4769
Suspicious Ticket Granting Ticket RequestHuntingNULLWindows Event Log Security 4768, Windows Event Log Security 4781
Windows AD User Suspicious UPN ChangeTTPNULLWindows Event Log Security 4738
Windows Group Policy Object CreatedTTPNULLWindows Event Log Security 5136, Windows Event Log Security 5137
Windows PowerView AD Access Control List EnumerationTTPNULLPowershell Script Block Logging 4104

Groups20

Software5

Campaigns10

Procedure examples35

Groups20

Used byProcedure example
GroupAgrius

Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement.

GroupAPT3

APT3 leverages valid accounts after gaining credentials for use within the victim domain.

GroupAPT5

APT5 has used legitimate account credentials to move laterally through compromised environments.

GroupAquatic Panda

Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments.

GroupBlackByte

BlackByte captured credentials for or impersonated domain administration users.

GroupChimera

Chimera has used compromised domain accounts to gain access to the target environment.

GroupCinnamon Tempest

Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware.

GroupIndrik Spider

Indrik Spider has collected credentials from infected systems, including domain accounts.

View all 20 groups examples

Software5

Used byProcedure example
MalwareCobalt Strike

Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account.

MalwareCreepySnail

CreepySnail can use stolen credentials to authenticate on target networks.

MalwareRyuk

Ryuk can use stolen domain admin accounts to move laterally within a victim domain.

MalwareShamoon

If Shamoon cannot access shares using current privileges, it attempts access using hard coded, domain-specific credentials gathered earlier in the intrusion.

MalwareStuxnet

Stuxnet attempts to access network resources with a domain account’s credentials.

Campaigns10

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, threat actors utilized privileged accounts to access the FortiGate VPN solution and subsequent subnets.

CampaignCutting Edge

During Cutting Edge, threat actors used compromised VPN accounts for lateral movement on targeted networks.

CampaignLeviathan Australian Intrusions

Leviathan compromised domain credentials during Leviathan Australian Intrusions.

CampaignNight Dragon

During Night Dragon, threat actors used domain accounts to gain further access to victim systems.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used compromised domain administrator credentials as part of their lateral movement.

CampaignOperation Ghost

For Operation Ghost, APT29 used stolen administrator credentials for lateral movement on compromised networks.

CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally.

CampaignOperation Wocao

During Operation Wocao, threat actors used domain credentials, including domain admin, for lateral movement and privilege escalation.

View all 10 campaigns examples

References2

  1. Microsoft AD Accounts Open source
    Microsoft. (2019, August 23). Active Directory Accounts. Retrieved March 13, 2020.
  2. TechNet Credential Theft Open source
    Microsoft. (2016, April 15). Attractive Accounts for Credential Theft. Retrieved June 3, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.