Additional Cloud Roles
An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments.(Citation: AWS IAM Policies and Permissions)(Citation: Google Cloud IAM Policies)(Citation: Microsoft Support O365 Add Another Admin, October 2019)(Citation: Microsoft O365 Admin Roles) With sufficient permissions, a compromi...
BY SOURCE
PROCEDURES (24)
Auto-extracted: 6 detections for azure
Auto-extracted: 6 detections for service
Auto-extracted: 4 detections for cloud
Auto-extracted: 4 detections for privilege
Auto-extracted: 3 detections for exfiltrat
Auto-extracted: 3 detections for api
Auto-extracted: 2 detections for persist
Auto-extracted: 2 detections for lateral
Auto-extracted: 2 detections for credential
Auto-extracted: 2 detections for bypass
Auto-extracted: 2 detections for email
Auto-extracted: 2 detections for persist
Auto-extracted: 2 detections for service
Auto-extracted: 2 detections for bypass
Auto-extracted: 2 detections for general monitoring
Auto-extracted: 1 detections for credential
Auto-extracted: 1 detections for api
Auto-extracted: 1 detections for authentication monitoring
Auto-extracted: 1 detections for azure
Auto-extracted: 1 detections for office
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for azure
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for exfiltrat