Valid Accounts, Technique T1078 - Enterprise | MITRE ATT&CK®
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop.[1] Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence. In some cases, adversaries may abuse inactive accounts: for example, those belonging to individuals who are no longer part of an organization. Using these accounts may allow the adversary to evade detection, as the original account user will not be p
Valid Accounts, Technique T1078 - Enterprise | MITRE ATT&CK® ATT&CKcon 7.0 is coming October 27-28, 2026. Learn more about ATT&CKcon 7.0 . Home Techniques Enterprise Valid Accounts Valid Accounts Sub-techniques (4) ID Name T1078.001 Default Accounts T1078.002 Domain Accounts T1078.003 Local Accounts T1078.004 Cloud Accounts Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the
related reading
- Initial Access, Tactic TA0001 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Account Manipulation, Technique T1098 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Persistence, Tactic TA0003 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert networkmicrosoft.com
- Remote Services, Technique T1021 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Threat actors misuse OAuth applications to automate financially driven attacksmicrosoft.com
- External Remote Services, Technique T1133 - Enterprise | MITRE ATT&CK®attack.mitre.org
- The Newest Instagram "Exploit" is the Goofiest I've Seen0xsid.com
- Trusted Relationship, Technique T1199 - Enterprise | MITRE ATT&CK®attack.mitre.org
- D3FEND Matrix | MITRE D3FEND™d3fend.mitre.org
- Why We Don’t Trust the Database With Authentication – Sturdy Statisticsblog.sturdystatistics.com