1200KM / simulation
T1098 Account Manipulation — Attack Simulation
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the…
Technique description
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Azure AD - adding user to Azure AD role
Procedure 0e65ae27-5385-46b4-98ac-607a8ee82261; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Azure - adding user to Azure role in subscription
Procedure 1a94b3fc-b080-450a-b3d8-6d9b57b472ea; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Admin Account Manipulate
Procedure 5598f7cb-cf43-455e-883a-f6008c5d46af; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Domain Password Policy Check: No Number in Password
Procedure 68190529-069b-4ffc-a942-919704158065; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Domain Password Policy Check: Only Two Character Classes
Procedure 784d1349-5a26-4d20-af5e-d6af53bae460; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Domain Password Policy Check: No Special Character in Password
Procedure 7d984ef2-2db2-4cec-b090-e637e1698f61; elevation not declared required; cleanup not declared. Not executed or individually validated.
- GCP - Delete Service Account Key
Procedure 7ece1dea-49f1-4d62-bdcc-5801e3292510; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Domain Password Policy Check: Common Password Use
Procedure 81959d03-c51f-49a1-bb24-23f1ec885578; elevation not declared required; cleanup not declared. Not executed or individually validated.
- AWS - Create a group and add a user to that group
Procedure 8822c3b0-d9f9-4daf-a043-49f110a31122; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Azure AD - adding service principal to Azure AD role
Procedure 92c40b3f-c406-4d1f-8d2b-c039bf5009e4; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Domain Password Policy Check: No Lowercase Character in Password
Procedure 945da11e-977e-4dab-85d2-f394d03c5887; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Azure AD - adding permission to application
Procedure 94ea9cc3-81f9-4111-8dde-3fb54f36af4b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Domain Account and Group Manipulate
Procedure a55a22e9-a3d3-42ce-bd48-2653adb8f7a9; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Domain Password Policy Check: No Uppercase Character in Password
Procedure b299c120-44a7-4d68-b8e2-8ba5a28511ec; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Azure - adding service principal to Azure role in subscription
Procedure c8f4bc29-a151-48da-b3be-4680af56f404; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Password Change on Directory Service Restore Mode (DSRM) Account
Procedure d5b886d9-d1c7-4b6e-a7b0-460041bf2823; elevation required; cleanup not declared. Not executed or individually validated.
- Domain Password Policy Check: Short Password
Procedure fc5f9414-bd67-4f5f-a08e-e5381e29cbd1; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.