flâneur — a map of the web's best reading

Account Manipulation, Technique T1098 - Enterprise | MITRE ATT&CK®

attack.mitre.org · 1,115 words · saved by 1 readers

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups.[1] These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials. In order to create or manipulate accounts, the adversary must already have sufficient permissions on systems or the domain. However, account manipulation may also lead to privilege escalation where modifications grant access to additional roles, permissions, or higher-privileged Valid Accounts. During the 2016 Ukraine Electric Power Attack, Sandworm Team used the sp_addlinkedsrvlogin command in MS-SQL to create a link between a created account and other servers in the network.[2] APT3 has been known to add creat

Account Manipulation, Technique T1098 - Enterprise | MITRE ATT&CK® ATT&CKcon 7.0 is coming October 27-28, 2026. Learn more about ATT&CKcon 7.0 . Home Techniques Enterprise Account Manipulation Account Manipulation Sub-techniques (7) ID Name T1098.001 Additional Cloud Credentials T1098.002 Additional Email Delegate Permissions T1098.003 Additional Cloud Roles T1098.004 SSH Authorized Keys T1098.005 Device Registration T1098.006 Additional Container Cluster Roles T1098.007 Additional Local or Domain Groups Adversaries may manipulate accounts to maintain and/or elevate access to victim system

Explore this link on the map →

related reading