{
  "technique_id": "T1078",
  "name": "Valid Accounts",
  "tactics": [
    "Initial Access",
    "Persistence",
    "Privilege Escalation",
    "Stealth"
  ],
  "platforms": [
    "Windows",
    "Linux",
    "macOS",
    "Azure AD",
    "Office 365",
    "SaaS"
  ],
  "summary": "Adversaries may obtain and abuse credentials of existing accounts as a means of gaining initial access, persistence, privilege escalation, or defense evasion. Compromised credentials can bypass access controls and blend in with legitimate activity, making valid account abuse hard to detect with signature-based tooling alone.\n",
  "generated_by": "SOC Response Atlas by Basyrix"
}