T1098 Account Manipulation — Detection & Response
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed so that credentials may be stolen later.
Coverage at a glance
- Detections shipped
- 5
- Avg. verdict time
- < 5 min
- Data sources
- 5+
Threat context
How adversaries use T1098 Account Manipulation — Detection & Response
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed so that credentials may be stolen later.
Account manipulation is a primary persistence mechanism after initial compromise. In cloud environments, attackers add new access keys to IAM users (T1098.001) or grant their controlled account admin roles (T1098.003) to create independent, persistent access that survives password resets. Email delegate permissions (T1098.002) are added to maintain mailbox access; device registration (T1098.005) creates a persistent authenticated device in Entra ID even after user credentials are rotated.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| New IAM Access Key Created — CreateAccessKey for existing user outside onboarding window A new IAM access key is created for an existing user, potentially by an attacker establishing persistent API access. | High | AWS CloudTrail |
| Admin Role Granted to User — Privileged role assignment in Entra ID or Okta A user is assigned a highly privileged role (Global Admin, Security Admin) outside of an approved change window. | Critical | Entra ID / Okta |
| Email Delegate Added — Mailbox full access or Send As permission granted A delegate permission is added to a mailbox, granting another account access to read or send email. | High | M365 Audit Log |
| New Device Registered to Entra ID — Unexpected device registration for user A new device is registered to Entra ID by a user account, potentially by an attacker registering an attacker-controlled device to establish persistence. | Medium | Entra ID Audit Log |
| SSH Public Key Added to Production Host — Authorized_keys modification on server A new SSH public key is added to authorized_keys on a production host outside of expected configuration management tooling. | High | Linux Audit Log / CrowdStrike |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1539 Steal Web Session Cookie — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response: frequently asked questions
How quickly does ManySignal detect account manipulation events?
Account manipulation events (role assignments, key creation) appear in CloudTrail and Entra audit logs within minutes. ManySignal processes these with sub-2-minute latency from the event timestamp, making real-time alerting on persistence establishment feasible.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.