1200KM / detection
T1078.004 Cloud Accounts — Detection Rules
Detection workspace for T1078.004 Cloud Accounts: 40 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Bitbucket User Login Failure · test · medium · {"product":"bitbucket","service":"audit","definition":"Requirements: \"Advance\" log level is required to receive these audit events."}
- Github New Secret Created · test · low · {"product":"github","service":"audit","definition":"Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"}
- Github Self Hosted Runner Changes Detected · test · low · {"product":"github","service":"audit","definition":"Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"}
- Github SSH Certificate Configuration Changed · test · medium · {"product":"github","service":"audit","definition":"Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"}
- AWS Successful Console Login Without MFA · experimental · medium · {"product":"aws","service":"cloudtrail"}
- AWS SAML Provider Deletion Activity · experimental · medium · {"product":"aws","service":"cloudtrail"}
- AWS IAM S3Browser LoginProfile Creation · test · high · {"product":"aws","service":"cloudtrail"}
- AWS IAM S3Browser Templated S3 Bucket Policy Creation · test · high · {"product":"aws","service":"cloudtrail"}
- AWS IAM S3Browser User or AccessKey Creation · test · high · {"product":"aws","service":"cloudtrail"}
- AWS Root Credentials · test · medium · {"product":"aws","service":"cloudtrail"}
- Azure Subscription Permission Elevation Via ActivityLogs · test · high · {"product":"azure","service":"activitylogs"}
- Bitlocker Key Retrieval · test · medium · {"product":"azure","service":"auditlogs"}
- Users Added to Global or Device Admin Roles · test · high · {"product":"azure","service":"auditlogs"}
- Application AppID Uri Configuration Changes · test · high · {"product":"azure","service":"auditlogs"}
- Application URI Configuration Changes · test · high · {"product":"azure","service":"auditlogs"}
- Guest User Invited By Non Approved Inviters · test · medium · {"product":"azure","service":"auditlogs"}
- User State Changed From Guest To Member · test · medium · {"product":"azure","service":"auditlogs"}
- PIM Approvals And Deny Elevation · test · high · {"product":"azure","service":"auditlogs"}
- Changes To PIM Settings · test · high · {"product":"azure","service":"auditlogs"}
- User Added To Privilege Role · test · high · {"product":"azure","service":"auditlogs"}
- Privileged Account Creation · test · medium · {"product":"azure","service":"auditlogs"}
- Temporary Access Pass Added To An Account · test · high · {"product":"azure","service":"auditlogs"}
- Password Reset By User Account · test · medium · {"product":"azure","service":"auditlogs"}
- Successful Authentications From Countries You Do Not Operate Out Of · test · medium · {"product":"azure","service":"signinlogs"}
- Device Registration or Join Without MFA · test · medium · {"product":"azure","service":"signinlogs"}
- Failed Authentications From Countries You Do Not Operate Out Of · test · low · {"product":"azure","service":"signinlogs"}
- Azure AD Only Single Factor Authentication Required · test · low · {"product":"azure","service":"signinlogs"}
- Sign-ins from Non-Compliant Devices · test · high · {"product":"azure","service":"signinlogs"}
- Sign-ins by Unknown Devices · test · low · {"product":"azure","service":"signinlogs"}
- Potential MFA Bypass Using Legacy Client Authentication · test · high · {"product":"azure","service":"signinlogs"}
- Account Disabled or Blocked for Sign in Attempts · test · medium · {"product":"azure","service":"signinlogs"}
- Sign-in Failure Due to Conditional Access Requirements Not Met · test · high · {"product":"azure","service":"signinlogs"}
- Use of Legacy Authentication Protocols · test · high · {"product":"azure","service":"signinlogs"}
- Login to Disabled Account · test · medium · {"product":"azure","service":"signinlogs"}
- Multifactor Authentication Denied · test · medium · {"product":"azure","service":"signinlogs"}
- Multifactor Authentication Interrupted · test · medium · {"product":"azure","service":"signinlogs"}
- User Access Blocked by Azure Conditional Access · test · medium · {"product":"azure","service":"signinlogs"}
- Users Authenticating To Other Azure AD Tenants · test · medium · {"product":"azure","service":"signinlogs"}
- Suspicious Login Activity Classified By Google · experimental · medium · {"product":"gcp","service":"google_workspace.login"}
- Okta New Admin Console Behaviours · test · high · {"product":"okta","service":"okta"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0546 Detection of Abused or Compromised Cloud Accounts for Access and Persistence
AN1503 Analytic 1503
Detects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts.
AN1504 Analytic 1504
Detects cloud account use for API calls that exceed normal scope, such as IAM changes or access to services never used before.
AN1505 Analytic 1505
Detects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users.
AN1506 Analytic 1506
Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.