M ManySignal
T1098 MITRE ATT&CK

T1098 Account Manipulation — Detection & Response

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed so that credentials may be stolen later.

Coverage at a glance

Detections shipped
5
Avg. verdict time
< 5 min
Data sources
5+

Threat context

How adversaries use T1098 Account Manipulation — Detection & Response

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed so that credentials may be stolen later.

Account manipulation is a primary persistence mechanism after initial compromise. In cloud environments, attackers add new access keys to IAM users (T1098.001) or grant their controlled account admin roles (T1098.003) to create independent, persistent access that survives password resets. Email delegate permissions (T1098.002) are added to maintain mailbox access; device registration (T1098.005) creates a persistent authenticated device in Entra ID even after user credentials are rotated.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

New IAM Access Key Created — CreateAccessKey for existing user outside onboarding window

A new IAM access key is created for an existing user, potentially by an attacker establishing persistent API access.

High AWS CloudTrail

Admin Role Granted to User — Privileged role assignment in Entra ID or Okta

A user is assigned a highly privileged role (Global Admin, Security Admin) outside of an approved change window.

Critical Entra ID / Okta

Email Delegate Added — Mailbox full access or Send As permission granted

A delegate permission is added to a mailbox, granting another account access to read or send email.

High M365 Audit Log

New Device Registered to Entra ID — Unexpected device registration for user

A new device is registered to Entra ID by a user account, potentially by an attacker registering an attacker-controlled device to establish persistence.

Medium Entra ID Audit Log

SSH Public Key Added to Production Host — Authorized_keys modification on server

A new SSH public key is added to authorized_keys on a production host outside of expected configuration management tooling.

High Linux Audit Log / CrowdStrike

T1098 Account Manipulation — Detection & Response: frequently asked questions

How quickly does ManySignal detect account manipulation events?

Account manipulation events (role assignments, key creation) appear in CloudTrail and Entra audit logs within minutes. ManySignal processes these with sub-2-minute latency from the event timestamp, making real-time alerting on persistence establishment feasible.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.