1200KM / tag
Identity Provider — platform tag
138 related reference pages for platform: Identity Provider.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- AADInternals · tool
- Active Directory Credential Request · telemetry
- Active Directory Object Access · telemetry
- Active Directory Object Creation · telemetry
- Active Directory Object Modification · telemetry
- Application Log Content · telemetry
- Cloud Service Disable · telemetry
- Cloud Service Enumeration · telemetry
- Cloud Service Metadata · telemetry
- Cloud Service Modification · telemetry
- Cloud Storage Access · telemetry
- Cloud Storage Metadata · telemetry
- Command Execution · telemetry
- evilginx2 · tool
- File Access · telemetry
- File Creation · telemetry
- File Metadata · telemetry
- File Modification · telemetry
- Group Enumeration · telemetry
- Group Metadata · telemetry
- Group Modification · telemetry
- Logon Session Creation · telemetry
- Logon Session Metadata · telemetry
- Module Load · telemetry
- Network Connection Creation · telemetry
- Network Traffic Content · telemetry
- Network Traffic Flow · telemetry
- OS API Execution · telemetry
- Process Access · telemetry
- Process Creation · telemetry
- Process Metadata · telemetry
- Process Modification · telemetry
- ROADTools · tool
- Script Execution · telemetry
- T1021.007 Cloud Services · simulation
- T1021.007 Cloud Services detections · detection
- T1036.010 Masquerade Account Name · simulation
- T1036.010 Masquerade Account Name detections · detection
- T1059 Command and Scripting Interpreter · simulation
- T1059 Command and Scripting Interpreter detections · detection
- T1059.009 Cloud API · simulation
- T1059.009 Cloud API detections · detection
- T1069 Permission Groups Discovery · simulation
- T1069 Permission Groups Discovery detections · detection
- T1069.003 Cloud Groups · simulation
- T1069.003 Cloud Groups detections · detection
- T1078 Valid Accounts · simulation
- T1078 Valid Accounts detections · detection
- T1078.001 Default Accounts · simulation
- T1078.001 Default Accounts detections · detection
- T1078.004 Cloud Accounts · simulation
- T1078.004 Cloud Accounts detections · detection
- T1087 Account Discovery · simulation
- T1087 Account Discovery detections · detection
- T1087.004 Cloud Account · simulation
- T1087.004 Cloud Account detections · detection
- T1098 Account Manipulation · simulation
- T1098 Account Manipulation detections · detection
- T1098.001 Additional Cloud Credentials · simulation
- T1098.001 Additional Cloud Credentials detections · detection
- T1098.003 Additional Cloud Roles · simulation
- T1098.003 Additional Cloud Roles detections · detection
- T1098.005 Device Registration · simulation
- T1098.005 Device Registration detections · detection
- T1110 Brute Force · simulation
- T1110 Brute Force detections · detection
- T1110.001 Password Guessing · simulation
- T1110.001 Password Guessing detections · detection
- T1110.002 Password Cracking · simulation
- T1110.002 Password Cracking detections · detection
- T1110.003 Password Spraying · simulation
- T1110.003 Password Spraying detections · detection
- T1110.004 Credential Stuffing · simulation
- T1110.004 Credential Stuffing detections · detection
- T1136 Create Account · simulation
- T1136 Create Account detections · detection
- T1136.003 Cloud Account · simulation
- T1136.003 Cloud Account detections · detection
- T1189 Drive-by Compromise · simulation
- T1189 Drive-by Compromise detections · detection
- T1199 Trusted Relationship · simulation
- T1199 Trusted Relationship detections · detection
- T1201 Password Policy Discovery · simulation
- T1201 Password Policy Discovery detections · detection
- T1212 Exploitation for Credential Access · simulation
- T1212 Exploitation for Credential Access detections · detection
- T1484 Domain or Tenant Policy Modification · simulation
- T1484 Domain or Tenant Policy Modification detections · detection
- T1484.002 Trust Modification · simulation
- T1484.002 Trust Modification detections · detection
- T1526 Cloud Service Discovery · simulation
- T1526 Cloud Service Discovery detections · detection
- T1528 Steal Application Access Token · simulation
- T1528 Steal Application Access Token detections · detection
- T1538 Cloud Service Dashboard · simulation
- T1538 Cloud Service Dashboard detections · detection
- T1548 Abuse Elevation Control Mechanism · simulation
- T1548 Abuse Elevation Control Mechanism detections · detection
- T1548.005 Temporary Elevated Cloud Access · simulation
- T1548.005 Temporary Elevated Cloud Access detections · detection
- T1550 Use Alternate Authentication Material · simulation
- T1550 Use Alternate Authentication Material detections · detection
- T1550.001 Application Access Token · simulation
- T1550.001 Application Access Token detections · detection
- T1552 Unsecured Credentials · simulation
- T1552 Unsecured Credentials detections · detection
- T1556 Modify Authentication Process · simulation
- T1556 Modify Authentication Process detections · detection
- T1556.006 Multi-Factor Authentication · simulation
- T1556.006 Multi-Factor Authentication detections · detection
- T1556.007 Hybrid Identity · simulation
- T1556.007 Hybrid Identity detections · detection
- T1556.009 Conditional Access Policies · simulation
- T1556.009 Conditional Access Policies detections · detection
- T1566 Phishing · simulation
- T1566 Phishing detections · detection
- T1566.002 Spearphishing Link · simulation
- T1566.002 Spearphishing Link detections · detection
- T1566.004 Spearphishing Voice · simulation
- T1566.004 Spearphishing Voice detections · detection
- T1606 Forge Web Credentials · simulation
- T1606 Forge Web Credentials detections · detection
- T1606.002 SAML Tokens · simulation
- T1606.002 SAML Tokens detections · detection
- T1621 Multi-Factor Authentication Request Generation · simulation
- T1621 Multi-Factor Authentication Request Generation detections · detection
- T1649 Steal or Forge Authentication Certificates · simulation
- T1649 Steal or Forge Authentication Certificates detections · detection
- T1685.002 Disable or Modify Cloud Log · simulation
- T1685.002 Disable or Modify Cloud Log detections · detection
- User Account Authentication · telemetry
- User Account Creation · telemetry
- User Account Metadata · telemetry
- User Account Modification · telemetry
- Web Credential Creation · telemetry
- Web Credential Usage · telemetry
- Windows Registry Key Access · telemetry
- Windows Registry Key Modification · telemetry
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.