| name | T1087.004_cloud-account |
| description | Adversaries may attempt to get a listing of cloud accounts. |
| category | information-gathering |
| version | 18.1 |
| author | cyberstrike-official |
| tags | ["mitre-attack","enterprise","t1087.004","discovery","iaas","identity-provider","office-suite","saas","sub-technique"] |
| technique_id | T1087.004 |
| tactic | discovery |
| all_tactics | ["discovery"] |
| platforms | ["IaaS","Identity Provider","Office Suite","SaaS"] |
| mitre_url | https://attack.mitre.org/techniques/T1087/004 |
| tech_stack | ["cloud","identity","office","saas"] |
| cwe_ids | ["CWE-200"] |
| chains_with | ["T1087","T1087.001","T1087.002","T1087.003"] |
| prerequisites | ["T1087"] |
| severity_boost | {"T1087":"Chain with T1087 for deeper attack path","T1087.001":"Chain with T1087.001 for deeper attack path","T1087.002":"Chain with T1087.002 for deeper attack path"} |
T1087.004 Cloud Account
Sub-technique of: T1087
High-Level Description
Adversaries may attempt to get a listing of cloud accounts. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application.
With authenticated access there are several tools that can be used to find accounts. The Get-MsolRoleMember PowerShell cmdlet can be used to obtain account names given a role or permissions group in Office 365. The Azure CLI (AZ CLI) also provides an interface to obtain user accounts with authenticated access to a domain. The command az ad user list will list all users within a domain.
The AWS command aws iam list-users may be used to obtain a list of users in the current account while aws iam list-roles can obtain IAM roles that have a specified path prefix. In GCP, gcloud iam service-accounts list and gcloud projects get-iam-policy may be used to obtain a listing of service accounts and users in a project.
Kill Chain Phase
Platforms: IaaS, Identity Provider, Office Suite, SaaS
What to Check
How to Test
Manual Testing
-
Identify Attack Surface: Determine if the target environment is susceptible to Cloud Account by examining the target platforms (IaaS, Identity Provider, Office Suite).
-
Assess Existing Defenses: Review whether mitigations for T1087.004 are in place. If defenses are absent or misconfigured, this technique may be exploitable.
-
Execute Test: Use tools and methods described in the MITRE ATT&CK page and external references below.