Basyrix SOC Response Atlas by Basyrix

Persistence · Privilege Escalation

T1098 — Account Manipulation

Adversaries may manipulate accounts — adding credentials, changing permissions, adding delegates or forwarding rules, or modifying group memberships — to maintain persistent access after an initial compromise.

Any unexpected credential, permission, or delegation change on an account should be treated as a potential persistence mechanism established after compromise, especially when it grants broader access or a secondary path back into the account.

Platforms

Windows, Azure AD, Office 365, SaaS

Priority / status

high / complete

Evidence to collect

  • Account affected
  • Type of change (credential/permission/delegation/group)
  • Initiating identity
  • Timestamp of change
  • Before/after state of the modified attribute