Basyrix SOC Response Atlas by Basyrix

Initial Access · Persistence · Privilege Escalation · Stealth

T1078 — Valid Accounts

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining initial access, persistence, privilege escalation, or defense evasion. Compromised credentials can bypass access controls and blend in with legitimate activity, making valid account abuse hard to detect with signature-based tooling alone.

Treat as potential account compromise. Validate sign-in activity, token usage, MFA changes, device posture, privilege changes, mailbox rules, OAuth grants, and lateral movement indicators before deciding whether this is expected user behaviour or an active intrusion.

Platforms

Windows, Linux, macOS, Azure AD, Office 365, SaaS

Priority / status

high / complete

Evidence to collect

  • User principal name
  • Source IP
  • Location
  • Device ID
  • User agent
  • Application accessed
  • Sign-in result
  • MFA status
  • Token activity
  • Group or role changes
  • Mailbox rule changes
  • OAuth consent grants