1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1098.001 Additional Cloud Credentials — Detection Rules

Detection workspace for T1098.001 Additional Cloud Credentials: 3 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

  • Github Outside Collaborator Detected · test · medium · {"product":"github","service":"audit","definition":"Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"}
  • Added Credentials to Existing Application · test · high · {"product":"azure","service":"auditlogs"}
  • Okta Identity Provider Created · test · medium · {"product":"okta","service":"okta"}

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0531 Detection Strategy for Additional Cloud Credentials in IaaS/IdP/SaaS

AN1469 Analytic 1469

Addition of credentials (keys, app passwords, x.509 certs) to existing cloud accounts, service principals, or OAuth apps via portal or API by non-standard identities or IP ranges.

AN1470 Analytic 1470

Cloud API usage to create/import SSH keys or generate new access keys (CreateAccessKey, ImportKeyPair, CreateLoginProfile) from non-console access or unusual principals.

AN1471 Analytic 1471

Credential-related configuration changes in productivity apps, such as API key creation in Google Workspace, app tokens in Slack, or user-level OAuth credentials in M365.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1098.001 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.