1200KM / detection
T1550 Use Alternate Authentication Material — Detection Rules
Detection workspace for T1550 Use Alternate Authentication Material: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- AWS STS AssumeRole Misuse · test · low · {"product":"aws","service":"cloudtrail"}
- AWS STS GetSessionToken Misuse · test · low · {"product":"aws","service":"cloudtrail"}
- AWS Suspicious SAML Activity · test · medium · {"product":"aws","service":"cloudtrail"}
- Outgoing Logon with New Credentials · test · low · {"product":"windows","service":"security"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0338 Behavioral Detection Strategy for Use Alternate Authentication Material (T1550)
AN0954 Analytic 0954
Use of stolen Kerberos tickets or token impersonation resulting in logon sessions from accounts without expected interactive logon events.
AN0955 Analytic 0955
Access tokens or SSH keys used without corresponding login shell or PAM module activity, particularly for remote execution.
AN0956 Analytic 0956
Token replay or impersonation in federated logins without interactive browser session or MFA prompts.
AN0957 Analytic 0957
Unusual reuse of OAuth access tokens from different geographic regions, without full login events.
AN0958 Analytic 0958
Container process uses mounted cloud credentials or token cache to authenticate without known orchestration.
AN0959 Analytic 0959
Access token reuse to connect to SharePoint or Outlook APIs without interactive user context.
AN0960 Analytic 0960
Use of instance metadata tokens across instances or misuse of short-lived tokens issued for different roles.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Application Log Content · DC0038
- Logon Session Creation · DC0067
- Process Creation · DC0032
- User Account Authentication · DC0002
- User Account Metadata · DC0013
- Web Credential Usage · DC0007
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.