If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1078 - Valid Accounts, Technique T107.

site address: attack.mitre.org/techniques/T1078 redirected to: attack.mitre.org/techniques/T1078

site title: Valid Accounts, Technique T1078 - Enterprise MITRE ATT&CK®

Our opinion (on Friday 21 August 2026 20:30:11 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

valid, accounts, procedure, examples, mitigations, detection, strategy, references, sub, techniques,

Text of the page (most frequently used words):
retrieved (103), and (85), the (67), credentials (59), used (55), access (51), has (47), #accounts (47), valid (34), 2024 (31), compromised (30), december (28), april (24), 2019 (24), 2021 (24), threat (24), may (24), for (24), june (21), group (21), victim (20), february (19), march (19), account (19), 2020 (18), august (18), network (18), 2022 (17), july (17), legitimate (17), october (16), 2017 (16), 2018 (15), 2025 (15), systems (15), gain (15), enterprise (14), cyber (14), during (14), september (13), with (13), vpn (13), 2026 (12), att (12), all (12), 2016 (12), 2023 (12), actors (12), infrastructure (12), security (12), november (12), initial (12), that (11), operation (11), 2015 (10), use (10), detection (10), cisa (10), remote (10), t1078 (10), actor (9), spider (9), from (9), attack (9), team (9), new (9), techniques (8), ransomware (8), research (8), persistence (8), targeting (8), activity (8), campaign (8), environments (8), across (8), user (8), are (7), data (7), microsoft (7), default (7), targets (7), maintain (7), operations (7), into (7), cloud (7), authentication (7), through (7), domain (7), not (7), using (7), ics (6), privileged (6), state (6), compromise (6), intelligence (6), espionage (6), organizations (6), january (6), applications (6), services (6), inc (6), tools (6), adversary (6), within (6), local (6), log (6), lateral (6), movement (6), networks (6), stolen (6), mobile (5), none (5), resources (5), tactics (5), privilege (5), critical (5), unc3886 (5), russian (5), global (5), service (5), against (5), alert (5), mcafee (5), fin6 (5), other (5), corporate (5), abuse (5), via (5), mfa (5), ssh (5), also (5), environment (5), adversaries (5), obtain (5), laterally (5), leviathan (5), mitre (4), defenses (4), administrative (4), intrusion (4), targeted (4), attacks (4), response (4), china (4), 2014 (4), night (4), multi (4), linux (4), malware (4), government (4), web (4), ransom (4), fin4 (4), analysis (4), apt (4), power (4), information (4), can (4), apt29 (4), exchange (4), akira (4), users (4), push (4), factor (4), should (4), have (4), policies (4), password (4), escalate (4), privileges (4), which (4), devices (4), void (4), manticore (4), email (4), move (4), version (4), reference (3), campaigns (3), groups (3), cti (3), mitigations (3), sub (3), core (3), cert (3), passwords (3), sponsored (3), persistent (3), unit (3), 3390 (3), teampcp (3), suckfly (3), star (3), blizzard (3), continues (3), phishing (3), associated (3), fireeye (3), solarwinds (3), supply (3), chain (3), multiple (3), silence (3), shinyhunters (3), symantec (3), seaduke (3), sea (3), turtle (3), mandiant (3), your (3), cybercrime (3), redpenguin (3), polonium (3), play (3), wocao (3), hacking (3), code (3), energy (3), dragon (3), cybersecurity (3), medusa (3), rabbit (3), lazarus (3), defense (3), lapsus (3), kinsing (3), industroyer (3), controls (3), evade (3), iranian (3), login (3), fin10 (3), duqu (3), dtrack (3), dragonfly (3), chimera (3), carbanak (3), blackbyte (3), axiom (3), report (3), apt41 (3), apt39 (3), apt33 (3), audit (3), anthropic (3), orchestrated (3), logins (3), windows (3), description (3), name (3), notifications (3), management (3), their (3), between (3), organization (3), leveraged (3), them (3), they (3), sandworm (3), indrik (3), various (3), c0032 (3), escalation (3), such (3), 3cx (3), corporation (2), domains (2), software (2), components (2), analytics (2), strategies (2), assets (2), matrices (2), objects (2), internet (2), conditional (2), prolific (2), carvey (2), prc (2), handala (2), linked (2), secureworks (2), worldwide (2), spear (2), disrupting (2), ongoing (2), ncsc (2), fbi (2), nsa (2), further (2), layered (2), evasive (2), attacker (2), moving (2), financially (2), motivated (2), extortion (2), incident (2), defending (2), unc3944 (2), guidance (2), juniper (2), routers (2), stopransomware (2), volexity (2), zero (2), day (2), exploitation (2), vulnerability (2), destructive (2), middle (2), east (2), davis (2), labs (2), 2011 (2), great (2), sophisticated (2), district (2), united (2), states (2), indictment (2), long (2), agency (2), apt40 (2), tradecraft (2), advisory (2), procedures (2), mstic (2), defender (2), container (2), america (2), industrial (2), profile (2), cybereason (2), providers (2), based (2), vulnerabilities (2), part (2), public (2), follow (2), crime (2), years (2), you (2), vengerik (2), street (2), likely (2), playing (2), market (2), advanced (2), single (2), detections (2), nutland (2), support (2), personal (2), brute (2), force (2), iot (2), two (2), adair (2), found (2), control (2), credential (2), protocols (2), unexpected (2), geographic (2), anomalies (2), sign (2), attempts (2), outside (2), patterns (2), anomalous (2), logon (2), types (2), platforms (2), analytic (2), only (2), any (2), longer (2), allow (2), these (2), been (2), created (2), different (2), employees (2), appliances (2), including (2), unauthorized (2), even (2), sensitive (2), wizard (2), volt (2), typhoon (2), prior (2), malicious (2), hijack (2), open (2), internal (2), silent (2), librarian (2), high (2), leverage (2), some (2), scattered (2), previously (2), pittytiger (2), midnighteclipse (2), oilrig (2), menupass (2), notes (2), australian (2), intrusions (2), obtained (2), administrator (2), restricted (2), rdp (2), ke3chang (2), search (2), create (2), homeland (2), justice (2), gallium (2), fox (2), kitten (2), fin8 (2), harvested (2), fin7 (2), fin5 (2), remotely (2), vpns (2), means (2), task (2), cinnamon (2), tempest (2), gained (2), outlook (2), apt28 (2), apt18 (2), ukraine (2), electric (2), 004 (2), 003 (2), 002 (2), 001 (2), bypass (2), those (2), ckcon (2), person (2), tickets (2), faq (2), registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, plett, poggemeyer, securing, material, implementing, least, models, risks, templates, shilko, fin12, aggressively, pursued, healthcare, john, unraveling, spiderweb, timelining, artifacts, grim, domaintools, investigations, mois, influence, ecosystem, assessment, check, point, hack, unveiling, modus, operandi, punsaen, boonyakarn, shawn, chew, logeswaran, nadarajan, mathew, potaczek, jakub, jozwiak, alex, marvi, cloaked, covert, uncovering, dell, counter, cyberespionage, eriksen, popular, telnyx, package, pypi, dimaggio, indian, fsb, seaborgium, ttps, svr, nafisi, lelli, goldmax, goldfinder, sibot, analyzing, nobelium, highly, leverages, victims, sunburst, backdoor, doj, rafatnejad, darkside, büyükkaya, calling, forkmeiamfamous, latest, weapon, duke, armory, cisco, talos, dns, hijacking, abuses, trust, help, desk, hypervisor, vmware, vsphere, estate, hardening, frontlines, 056, ukrainian, censys, junos, lamparski, ghost, router, nexus, exposing, israeli, aa23, 352a, bizeul, fontarensky, mouchoux, perigaud, pernet, eye, tiger, dantzig, schamper, shining, light, one, hidden, unauthenticated, execution, globalprotect, cve, 3400, kessem, wiper, zerocleare, sector, caban, apt34, unit42, serpens, playbook, viewer, foundstone, professional, cyberattacks, apt10, loader, ecipekac, discovered, a41apt, court, southern, york, zhu, hua, japan, running, pwc, bae, hopper, aa25, 071a, eset, muddywater, snakes, riverbank, anomali, pulling, rabbot, out, hat, people, republic, ministry, action, accenture, idefense, mudcarp, focus, submarine, technologies, aa21, 200a, joint, indicted, mss, hainan, department, vyacheslav, kopeytsev, seongsu, park, industry, threatneedle, brown, recent, dart, m365, dev, 0537, criminal, exfiltration, destruction, singer, nickel, latin, europe, anton, cherepanov, win32, hades, back, unc2165, shifts, lockbit, sanctions, lolbin, socradar, dark, huntress, investigating, aa22, 264a, conduct, albania, nocturnus, soft, cell, telecommunications, iran, exploits, elovitz, ahl, know, enemy, loui, reynolds, carbon, embraces, big, game, hunting, visa, expands, ecommerce, merchants, mckeague, pick, six, intercepting, recently, tied, ryuk, lockergoga, money, dissecting, bromiley, lewis, attacking, hospitality, gaming, industries, tracking, around, world, higgins, gang, favors, legit, scavella, rifki, ready, respond, webinar, dennesen, isight, anatomy, w32, precursor, next, stuxnet, hod, gavriel, depth, nuclear, plant, compromises, slowik, baffling, berserk, bear, decade, ta18, 074a, sectors, biderman, revealing, emperor, sky, cheerscrypt, cycraft, skeleton, key, taiwan, semiconductor, vendors, kaspersky, lab, bank, robbery, miller, triton, ttp, custom, mapping, james, craig, jackson, terryn, valikodath, brennan, evans, blends, tried, true, newly, disclosed, novetta, smn, crowdstrike, fraser, double, dragonapt41, dual, hawley, focused, ackerman, overruled, containing, potentially, carr, insights, douglas, bienstock, 365, gru, conducting, msrc, path, mueller, viktor, borisovich, netyksho, hacquebord, pawn, storm, examining, increasingly, relevant, detecting, responding, threats, first, reported, szeliga, evolve, steven, campbell, akshay, suthar, connor, belfiorre, conti, chained, together, gold, sahara, agathocles, prodromou, update, thursday, vector, electricity, sharing, center, sans, ukranian, grid, case, attractive, theft, exploiting, multifactor, printnightmare, lancaster, driftingcloud, sophos, firewall, insidious, breach, references, containerized, kubeconfigs, being, cluster, nodes, ips, an1547, idp, logs, impossible, travel, risky, ins, failures, an1546, interactive, unusual, times, child, process, an1545, misuse, sudo, expected, an1544, misused, abnormal, inconsistent, time, endpoints, an1543, det0560, strategy, send, verify, form, train, accept, suspicious, training, m1017, regularly, deactivate, remove, needed, m1018, well, permission, levels, routinely, look, situations, could, wide, obtaining, audits, include, enabled, authorized, best, practices, design, administration, limit, tiers, 103, 102, m1026, minimize, eliminate, reuse, especially, same, defended, utilize, username, changed, immediately, after, installation, before, deployment, production, when, possible, keys, updated, periodically, properly, secured, 101, m1027, implement, prevent, provides, layer, requiring, forms, verification, beyond, just, this, measure, significantly, reduces, risk, abusing, m1032, ensure, store, insecurely, plaintext, published, repositories, storage, application, developer, m1013, disable, legacy, does, require, modern, instead, active, directory, configuration, m1015, block, non, compliant, defined, ranges, 100, m1036, mitigation, goal, accessing, controllers, g0102, relies, primarily, g1017, validated, tested, actions, g1055, g1048, variety, methods, g0027, source, scanning, had, g1056, dumped, navigate, though, were, owner, g0039, g1033, c0024, online, g0122, g0091, sso, negotiations, g1057, samples, module, extract, servers, s0053, term, g1041, g1015, acquired, g0034, priviliged, c0056, g1005, achieve, g1040, g0011, c0014, extracted, while, c0048, g0049, c0002, shared, managed, clients, g0045, utilized, facilitate, sometimes, combination, psexec, g1051, s9036, acquires, s0362, captured, c0049, g0065, segments, g0032, session, tokens, vdi, iams, g1004, hosts, s0599, dumpers, stealers, g0004, supplied, execute, processes, stop, s0604, maintained, g0119, g1032, mailboxes, c0038, g0093, g0117, g0061, g0046, gathered, usernames, hashes, g0037, citrix, vnc, g0053, communications, g0085, connect, protected, g0051, instruct, spread, copying, itself, shares, enumerated, keylogging, host, then, infected, schedule, machines, executes, s0038, hard, coded, share, s0567, g0035, deploy, payloads, system, g1021, scheduled, g0114, banking, perform, sent, millions, dollars, g0008, temp, veles, g1043, g0001, g0096, owa, g0087, g0064, g0016, exfiltrate, specifically, spearphishing, dccc, manufacturer, voip, phone, printer, video, decoder, g0007, external, g0026, authenticate, apis, database, registries, logging, c0062, uses, g1024, applejeus, c0057, establish, c0028, procedure, examples, live, permalink, last, modified, jon, sternstein, stern, mark, wee, menachem, goldstein, netskope, praetorian, prasad, somasamudram, sekhar, sarukkai, syed, ummar, farooqh, yossi, weizman, azure, contributors, containers, esxi, iaas, identity, provider, office, suite, saas, macos, stealth, overlap, permissions, concern, because, able, pivot, reach, level, set, cases, inactive, example, belonging, individuals, who, original, will, present, identify, taking, place, existing, gaining, evasion, placed, externally, available, desktop, grant, increased, specific, areas, choose, conjunction, provide, make, harder, detect, presence, home, join, mclean, hotel, location, details, register, here, blog, contribute, benefactors, legal, branding, updates, history, engage, council, learn, more, about, get, started, technique,


Text of the page (random words):
organization using these accounts may allow the adversary to evade detection as the original account user will not be present to identify any anomalous activity taking place on their account 2 the overlap of permissions for local domain and cloud accounts across a network of systems is of concern because the adversary may be able to pivot across accounts and systems to reach a high level of access i e domain or enterprise administrator to bypass access controls set within the enterprise 3 id t1078 sub techniques t1078 001 t1078 002 t1078 003 t1078 004 ⓘ tactics stealth persistence privilege escalation initial access ⓘ platforms containers esxi iaas identity provider linux network devices office suite saas windows macos contributors jon sternstein stern security mark wee menachem goldstein netskope praetorian prasad somasamudram mcafee sekhar sarukkai mcafee syed ummar farooqh mcafee yossi weizman azure defender research team version 3 0 created 31 may 2017 last modified 12 may 2026 version permalink live version procedure examples id name description c0028 2015 ukraine electric power attack during the 2015 ukraine electric power attack sandworm team used valid accounts on the corporate network to escalate privileges move laterally and establish persistence within the corporate network 4 c0057 3cx supply chain attack during 3cx supply chain attack applejeus has gained access to the 3cx corporate environment through legitimate vpn credentials 5 g1024 akira akira uses valid account information to remotely access victim networks such as vpn credentials 6 7 8 c0062 anthropic ai orchestrated campaign during the anthropic ai orchestrated campaign the adversary used harvested credentials to authenticate against internal apis database systems container registries and logging infrastructure across targeted networks 9 g0026 apt18 apt18 actors leverage legitimate credentials to log into external remote services 10 g0007 apt28 apt28 has used legitimate credentials to gain initial access maintain access and exfiltrate data from a victim network the group has specifically used credentials stolen through a spearphishing email to login to the dccc network the group has also leveraged default manufacturer s passwords to gain initial access to corporate networks via iot devices such as a voip phone printer and video decoder 11 12 13 14 g0016 apt29 apt29 has used a compromised account to access an organization s vpn infrastructure 15 g0064 apt33 apt33 has used valid accounts for initial access and privilege escalation 16 17 g0087 apt39 apt39 has used stolen credentials to compromise outlook web access owa 18 g0096 apt41 apt41 used compromised credentials to log on to other systems 19 20 g0001 axiom axiom has used previously compromised administrative accounts to escalate privileges 21 g1043 blackbyte blackbyte has gained access to victim environments through legitimate vpn credentials 22 c0032 c0032 during the c0032 campaign temp veles used compromised vpn accounts 23 g0008 carbanak carbanak actors used legitimate credentials of banking employees to perform operations that sent them millions of dollars 24 g0114 chimera chimera has used a valid account to maintain persistence via scheduled task 25 g1021 cinnamon tempest cinnamon tempest has used compromised user accounts to deploy payloads and create system services 26 g0035 dragonfly dragonfly has compromised user credentials and used valid accounts for operations 27 28 29 s0567 dtrack dtrack used hard coded credentials to gain access to a network share 30 s0038 duqu adversaries can instruct duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials via keylogging or other means the remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware 31 g0051 fin10 fin10 has used stolen credentials to connect remotely to victim networks using vpns protected with only a single factor 32 g0085 fin4 fin4 has used legitimate credentials to hijack email communications 33 34 g0053 fin5 fin5 has used legitimate vpn rdp citrix or vnc credentials to maintain access to a victim environment 35 36 37 g0037 fin6 to move laterally on a victim network fin6 has used credentials stolen from various systems on which it gathered usernames and password hashes 38 39 40 g0046 fin7 fin7 has harvested valid administrative credentials for lateral movement 41 g0061 fin8 fin8 has used valid accounts for persistence and lateral movement 42 g0117 fox kitten fox kitten has used valid credentials with various services during lateral movement 43 g0093 gallium gallium leveraged valid accounts to maintain access to a victim network 44 c0038 homeland justice during homeland justice threat actors used a compromised exchange account to search mailboxes and create new exchange accounts 45 g1032 inc ransom inc ransom has used compromised valid accounts for access to victim environments 46 47 48 49 g0119 indrik spider indrik spider has used valid accounts for initial access and lateral movement 50 indrik spider has also maintained access to the victim environment through the vpn infrastructure 50 s0604 industroyer industroyer can use supplied user credentials to execute processes and stop services 51 g0004 ke3chang ke3chang has used credential dumpers or stealers to obtain legitimate credentials which they used to gain access to victim accounts 52 s0599 kinsing kinsing has used valid ssh credentials to access remote hosts 53 g1004 lapsus lapsus has used compromised credentials and or session tokens to gain access into a victim s vpn vdi rdp and iams 54 55 g0032 lazarus group lazarus group has used administrator credentials to gain access to restricted network segments 56 g0065 leviathan leviathan has obtained valid accounts to gain initial access 57 58 59 c0049 leviathan australian intrusions leviathan used captured valid account information to log into victim web applications and appliances during leviathan australian intrusions 59 s0362 linux rabbit linux rabbit acquires valid ssh accounts through brute force 60 s9036 lp notes lp notes has used stolen windows credentials to log in as the users 61 g1051 medusa group medusa group has utilized compromised legitimate local and domain accounts within the victim environment to facilitate remote access and lateral movement sometimes in combination with psexec 62 g0045 menupass menupass has used valid accounts including shared between managed service providers and clients to move between the two environments 63 64 65 66 c0002 night dragon during night dragon threat actors used compromised vpn accounts to gain access to victim systems 67 g0049 oilrig oilrig has used compromised credentials to access other systems on a victim network 68 69 20 70 c0048 operation midnighteclipse during operation midnighteclipse threat actors extracted sensitive credentials while moving laterally through compromised networks 71 c0014 operation wocao during operation wocao threat actors used valid vpn credentials to gain initial access 72 g0011 pittytiger pittytiger attempts to obtain legitimate credentials during operations 73 g1040 play play has used valid vpn accounts to achieve initial access 74 g1005 polonium polonium has used valid compromised credentials to gain access to victim environments 75 c0056 redpenguin during redpenguin unc3886 used legitimate credentials to gain priviliged access to juniper routers 76 77 g0034 sandworm team sandworm team have used previously acquired legitimate credentials prior to attacks 78 g1015 scattered spider scattered spider has used compromised credentials for initial access 79 80 g1041 sea turtle sea turtle used compromised credentials to maintain long term access to victim environments 81 s0053 seaduke some seaduke samples have a module to extract email from microsoft exchange servers using compromised credentials 82 g1057 shinyhunters shinyhunters has used valid high privileged sso users as leverage during negotiations 83 g0091 silence silence has used compromised credentials to log on to other systems and escalate privileges 84 g0122 silent librarian silent librarian has used compromised credentials to obtain unauthorized access to online accounts 85 c0024 solarwinds compromise during the solarwinds compromise apt29 used different compromised credentials for remote access and to move laterally 86 87 88 g1033 star blizzard star blizzard has used stolen credentials to sign into victim email accounts 89 90 g0039 suckfly suckfly used legitimate account credentials that they dumped to navigate the internal victim network as though they were the legitimate account owner 91 g1056 teampcp teampcp has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to 92 g0027 threat group 3390 threat group 3390 actors obtain legitimate credentials using a variety of methods and use them to further lateral movement on victim networks 93 g1048 unc3886 unc3886 has used tools to hijack valid ssh accounts 94 g1055 void manticore void manticore has leveraged valid accounts to log into vpn infrastructure 95 void manticore has used compromised valid credentials to gain access to management infrastructure and enterprise control systems 96 void manticore has also validated and tested authentication using compromised credentials prior to malicious actions 95 g1017 volt typhoon volt typhoon relies primarily on valid credentials for persistence 97 g0102 wizard spider wizard spider has used valid credentials for privileged accounts with the goal of accessing domain controllers 98 99 mitigations id mitigation description m1036 account use policies use conditional access policies to block logins from non compliant devices or from outside defined organization ip ranges 100 m1015 active directory configuration disable legacy authentication which does not support mfa and require the use of modern authentication protocols instead m1013 application developer guidance ensure that applications do not store sensitive data or credentials insecurely e g plaintext credentials in code published credentials in repositories or credentials in public cloud storage m1032 multi factor authentication implement multi factor authentication mfa across all account types including default local domain and cloud accounts to prevent unauthorized access even if credentials are compromised mfa provides a critical layer of security by requiring multiple forms of verification beyond just a password this measure significantly reduces the risk of adversaries abusing valid accounts to gain initial access escalate privileges maintain persistence or evade defenses within your network m1027 password policies applications and appliances that utilize default username and password should be changed immediately after the installation and before deployment to a production environment 101 when possible applications that use ssh keys should be updated periodically and properly secured policies should minimize if not eliminate reuse of passwords between different user accounts especially employees using the same credentials for personal accounts that may not be defended by enterprise security resources m1026 privileged account management audit domain and local accounts as well as their permission levels routinely to look for situations that could allow an adversary to gain wide access by obtaining credentials of a privileged account 3 102 these audits should also include if default accounts have been enabled or if new local accounts are created that have not been authorized follow best practices for design and administration of an enterprise network to limit privileged account use across administrative tiers 103 m1018 user account management regularly audit user accounts for activity and deactivate or remove any that are no longer needed m1017 user training applications may send push notifications to verify a login as a form of multi factor authentication mfa train users to only accept valid push notifications and to report suspicious push notifications detection strategy id name analytic id analytic description det0560 detection of valid account abuse across platforms an1543 detection of compromised or misused valid accounts via anomalous logon patterns abnormal logon types and inconsistent geographic or time based activity across windows endpoints an1544 detection of valid account misuse through ssh logins sudo su abuse and service account anomalies outside expected patterns an1545 detection of interactive and remote logins by service accounts or users at unusual times with unexpected child process activity an1546 detection of valid account abuse in idp logs via geographic anomalies impossible travel risky sign ins and multiple mfa attempts or failures an1547 detection of containerized service accounts or compromised kubeconfigs being used for cluster access from unexpected nodes or ips references adair s lancaster t volexity threat research 2022 june 15 driftingcloud zero day sophos firewall exploitation and an insidious breach retrieved july 1 2022 cybersecurity and infrastructure security agency 2022 march 15 russian state sponsored cyber actors gain network access by exploiting default multifactor authentication protocols and printnightmare vulnerability retrieved march 16 2022 microsoft 2016 april 15 attractive accounts for credential theft retrieved june 3 2016 electricity information sharing and analysis center sans industrial control systems 2016 march 18 analysis of the cyber attack on the ukranian power grid defense use case retrieved march 27 2018 agathocles prodromou 2023 april 20 security update thursday 20 april 2023 initial intrusion vector found retrieved august 25 2025 secureworks n d gold sahara retrieved february 20 2024 steven campbell akshay suthar connor belfiorre 2023 july 26 conti and akira chained together retrieved february 20 2024 nutland j and szeliga m 2024 october 21 akira ransomware continues to evolve retrieved december 10 2024 anthropic 2025 november disrupting the first reported ai orchestrated cyber espionage campaign retrieved april 20 2026 adair s 2017 february 17 detecting and responding to advanced threats within exchange environments retrieved november 17 2024 hacquebord f 2017 april 25 two years of pawn storm examining an increasingly relevant threat retrieved may 3 2017 mueller r 2018 july 13 indictment united states of america vs viktor borisovich netyksho et al retrieved november 17 2024 msrc team 2019 august 5 corporate iot a path to intrusion retrieved august 16 2019 nsa cisa fbi ncsc 2021 july russian gru conducting global brute force campaign to compromise enterprise and cloud environments retrieved july 26 2021 douglas bienstock 2022 august 18 you can t audit me apt29 continues targeting microsoft 365 retrieved february 23 2023 davis s and carr n 2017 septem...
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 131 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
101-105 106-110 111-115 116-120 121-125 126-130 131-131


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


The site also has 57 references to external domain(s).

 medium.com  Verify  na.eventscloud.com  Verify  volexity.com  Verify
 cisa.gov  Verify  technet.microsoft.com  Verify  nsarchive.gwu.edu  Verify
 3cx.com  Verify  secureworks.com  Verify  arcticwolf.com  Verify
 blog.talosintelligence.com  Verify  assets.anthropic.com  Verify  web.archive.org  Verify
 documents.trendmicro.com  Verify  cdn.cnn.com  Verify  msrc-blog.microsoft.com  Verify
 media.defense.gov  Verify  mandiant.com  Verify  brighttalk.com  Verify
 fireeye.com  Verify  go.crowdstrike.com  Verify  media.kasperskycontenthub.com  Verify
 blog.sygnia.co  Verify  us-cert.gov  Verify  vblocalhost.com  Verify
 cyberbit.com  Verify  symantec.com  Verify  services.google.com  Verify
 www2.fireeye.com  Verify  darkreading.com  Verify  youtube.com  Verify
 usa.visa.com  Verify  crowdstrike.com  Verify  us-cert.cisa.gov  Verify
 cybereason.com  Verify  huntress.com  Verify  socradar.io  Verify
 cloud.google.com  Verify  welivesecurity.com  Verify  microsoft.com  Verify
 blog.aquasec.com  Verify  nccgroup.com  Verify  securelist.com  Verify
 anomali.com  Verify  symantec-enterprise-blogs.security.com  Verify  justice.gov  Verify
 scadahacker.com  Verify  fox-it.com  Verify  censys.com  Verify
 blog.eclecticiq.com  Verify  go.group-ib.com  Verify  ncsc.gov.uk  Verify
 aikido.dev  Verify  research.checkpoint.com  Verify  dti.domaintools.com  Verify
 learn.microsoft.com  Verify  x.com  Verify  github.com  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1078
X-GitHub-Request-Id 69DC:1DC368:47050:4A5F5:6A88B552
x-github-edge-region uksouth
Accept-Ranges bytes
Age 0
Date Fri, 21 Aug 2026 20:30:11 GMT
Via 1.1 varnish
X-Served-By cache-lcy-egml8630027-LCY
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787344211.016193,VS0,VE85
Vary Accept-Encoding
X-Fastly-Request-ID 303843bac874c7e5e404ede974c681b82ed631cc
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1078/
access-control-allow-origin *
expires Fri, 21 Aug 2026 20:40:11 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id FED0:1459C1:2FF454:3047EC:6A88B553
x-github-edge-region fra
accept-ranges bytes
age 0
date Fri, 21 Aug 2026 20:30:11 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290032-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787344211.129764,VS0,VE108
vary Accept-Encoding
x-fastly-request-id 20338582be87cefda92d1b03a5b52b9208a810e4
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:18 GMT
access-control-allow-origin *
etag W/ 6a75ea92-2dadf
expires Fri, 21 Aug 2026 20:40:11 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 5A46:16B7D6:30F331:314687:6A88B552
x-github-edge-region fra
accept-ranges bytes
age 0
date Fri, 21 Aug 2026 20:30:11 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290032-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787344211.246111,VS0,VE116
vary Accept-Encoding
x-fastly-request-id b7121d3417bbfc3f88677b5e42ca668f455ef9b9
content-length 36254

Meta Tags

title="Valid Accounts, Technique T1078 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size36254
load time (s)0.84506
redirect count2
speed download42904
server IP 185.199.111.153
* all occurrences of the string "http://" have been changed to "htt???/"