Trusted Relationship, Technique T1199 - Enterprise | MITRE ATT&CK®
Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network. Organizations often grant elevated access to second or third-party external providers in order to allow them to manage internal systems as well as cloud-based environments. Some examples of these relationships include IT services contractors, managed security providers, infrastructure contractors (e.g. HVAC, elevators, physical security). The third-party provider's access may be intended to be limited to the infrastructure being maintained, but may exist on the same network as the rest of the enterprise. As such, Valid Accounts used by the other party for access to internal network systems may be compromised and used.[1] In Office 365 environments, organizations may grant Microsoft partners or resellers dele
Trusted Relationship, Technique T1199 - Enterprise | MITRE ATT&CK® ATT&CKcon 7.0 is coming October 27-28, 2026. Learn more about ATT&CKcon 7.0 . Home Techniques Enterprise Trusted Relationship Trusted Relationship Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network. Organizations often grant elevated access to second or third-party external providers in order to a
Explore this link on the map →related reading
- Valid Accounts, Technique T1078 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Initial Access, Tactic TA0001 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Account Manipulation, Technique T1098 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Third-Party Security Risk Management: 7 Best Practices | Sytecaekransystem.com
- Security incident disclosure — July 2026huggingface.co
- Entra ID service principals in business email compromise schemes | Red Canaryredcanary.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Common Oauth Apps Used in Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- External Remote Services, Technique T1133 - Enterprise | MITRE ATT&CK®attack.mitre.org
- D3FEND Matrix | MITRE D3FEND™d3fend.mitre.org
- Remote Services, Technique T1021 - Enterprise | MITRE ATT&CK®attack.mitre.org