1200KM / simulation
T1136.003 Cloud Account — Attack Simulation
Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system. In addition to user accounts, cloud accounts may be associated with services. Cloud providers handle the concept of service accounts in different ways. In Azure, service accounts…
Technique description
Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system. In addition to user accounts, cloud accounts may be associated with services. Cloud providers handle the concept of service accounts in different ways. In Azure, service accounts…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Azure AD - Create a new user via Azure CLI
Procedure 228c7498-be31-48e9-83b7-9cb906504ec8; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- AWS - Create a new IAM user
Procedure 8d1c2368-b503-40c9-9057-8e42f21c58ad; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Azure AD - Create a new user
Procedure e62d23ef-3153-4837-8625-fa4a3829134d; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.