1200KM / detection
T1098.003 Additional Cloud Roles — Detection Rules
Detection workspace for T1098.003 Additional Cloud Roles: 7 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Github Outside Collaborator Detected · test · medium · {"product":"github","service":"audit","definition":"Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"}
- User Added to an Administrator's Azure AD Role · test · medium · {"product":"azure","service":"activitylogs"}
- Granting Of Permissions To An Account · test · medium · {"product":"azure","service":"activitylogs"}
- App Granted Privileged Delegated Or App Permissions · test · high · {"product":"azure","service":"auditlogs"}
- App Assigned To Azure RBAC/Microsoft Entra Role · test · medium · {"product":"azure","service":"auditlogs"}
- Google Workspace Application Access Level Modified · test · medium · {"product":"gcp","service":"google_workspace.admin"}
- Okta Admin Role Assigned to an User or Group · test · medium · {"product":"okta","service":"okta"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0277 Detection Strategy for Role Addition to Cloud Accounts
AN0771 Analytic 0771
Detection of new IAM roles or policies attached to a user/service in AWS/GCP/Azure outside normal patterns or hours, often following account compromise.
AN0772 Analytic 0772
Behavioral chain of a user being granted elevated privileges or roles in Entra ID or Okta following suspicious login or account creation activity.
AN0773 Analytic 0773
Detection of new admin or role assignment actions within Microsoft 365/O365 environments to elevate access for persistence or lateral movement.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1098.003 simulation workspace
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.