MITRE ATT&CK T1078 Valid Accounts Explained
ID: b9a67696-d6fc-53c7-bec8-c65bb54586b0
STIX ID: report--b9a67696-d6fc-53c7-bec8-c65bb54586b0
Feed Name: Resources-2
Date Published: 2026-02-03
Date Updated: 2026-07-22
Author: [email protected] (Sıla Özeren Hacıoğlu)
This report analyzes MITRE ATT&CK T1078 (Valid Accounts) and its four sub-techniques (default, domain, local, cloud), documents real-world abuse by multiple ransomware groups and APTs (e.g., DragonForce, Scattered Spider, Silk Typhoon, WARP PANDA), and highlights that credential-based access is highly effective and difficult to detect (citing a 98% success rate in tests). It emphasizes identity and cloud accounts as primary attack surfaces, details common adversary behaviors (credential theft, MFA abuse, service principal/OAuth misuse), and recommends validating identity-abuse paths rather than relying solely on vulnerability severity scoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
