Meta tags:
Headings (most frequently used words):
compromise, accounts, mitigations, detection, strategy, references, sub, techniques,
Text of the page (most frequently used words):
accounts (18), the (12), att (10), and (10), all (10), for (10), may (10), enterprise (8), #compromise (8), t1586 (8), detection (6), #techniques (6), ics (5), mobile (5), none (5), with (5), mitre (4), data (4), defenses (4), social (4), organization (4), this (4), traffic (4), that (4), phishing (4), version (4), adversaries (4), credentials (4), cti (3), mitigations (3), sub (3), march (3), activity (3), your (3), patterns (3), protocol (3), not (3), anomalous (3), october (3), compromised (3), information (3), persona (3), 2026 (2), corporation (2), are (2), use (2), domains (2), resources (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), 2022 (2), targeting (2), retrieved (2), consider (2), monitoring (2), media (2), related (2), include (2), personas (2), modified (2), making (2), outside (2), such (2), during (2), access (2), monitor (2), associated (2), flows (2), command (2), line (2), analytic (2), description (2), name (2), technique (2), controls (2), pre (2), development (2), 003 (2), 002 (2), 001 (2), email (2), exist (2), sites (2), further (2), incorporating (2), compromising (2), from (2), about (2), can (2), existing (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, microsoft, dev, 0537, criminal, actor, organizations, exfiltration, destruction, bright, 2011, february, anonymous, speaks, inside, story, hbgary, hack, 2017, references, suspicious, claiming, work, recently, numerous, connection, requests, affiliated, much, will, take, place, visibility, target, behavior, difficult, efforts, focused, stages, adversary, lifecycle, initial, analyze, packet, inspection, follow, expected, standards, extraneous, packets, belong, established, gratuitous, syntax, structure, correlation, process, detect, processes, execution, arguments, anomalies, files, normally, initiate, connections, respective, an2008, det0876, strategy, cannot, easily, mitigated, preventive, since, based, behaviors, performed, scope, m1056, mitigation, live, permalink, 2025, last, 2020, created, platforms, resource, tactic, directly, leverage, single, site, across, multiple, facebook, linkedin, twitter, google, etc, require, additional, could, filling, out, modifying, profile, developing, networks, photos, variety, methods, gathering, via, purchasing, third, party, brute, forcing, password, reuse, breach, credential, dumps, paying, employees, suppliers, business, partners, prior, conduct, reconnaissance, inform, decisions, which, their, operation, services, used, operations, engineering, utilization, online, important, rather, than, creating, cultivating, utilizing, engender, level, trust, potential, victim, they, have, relationship, knowledge, establish, cloud, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, get, started, detections,
Text of the page (random words):
compromise accounts technique t1586 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise compromise accounts compromise accounts sub techniques 3 id name t1586 001 social media accounts t1586 002 email accounts t1586 003 cloud accounts adversaries may compromise accounts with services that can be used during targeting for operations incorporating social engineering the utilization of an online persona may be important rather than creating and cultivating accounts i e establish accounts adversaries may compromise existing accounts utilizing an existing persona may engender a level of trust in a potential victim if they have a relationship or knowledge of the compromised persona a variety of methods exist for compromising accounts such as gathering credentials via phishing for information purchasing credentials from third party sites brute forcing credentials ex password reuse from breach credential dumps or paying employees suppliers or business partners for access to credentials 1 2 prior to compromising accounts adversaries may conduct reconnaissance to inform decisions about which accounts to compromise to further their operation personas may exist on a single site or across multiple sites ex facebook linkedin twitter google etc compromised accounts may require additional development this could include filling out or modifying profile information further developing social networks or incorporating photos adversaries may directly leverage compromised email accounts for phishing for information or phishing id t1586 sub techniques t1586 001 t1586 002 t1586 003 ⓘ tactic resource development ⓘ platforms pre version 1 2 created 01 october 2020 last modified 24 october 2025 version permalink live version mitigations id mitigation description m1056 pre compromise this technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls detection strategy id name analytic id analytic description det0876 detection of compromise accounts an2008 consider monitoring social media activity related to your organization suspicious activity may include personas claiming to work for your organization or recently modified accounts making numerous connection requests to accounts affiliated with your organization much of this activity will take place outside the visibility of the target organization making detection of this behavior difficult detection efforts may be focused on related stages of the adversary lifecycle such as during initial access ex phishing monitor and analyze traffic patterns and packet inspection associated to protocol s that do not follow the expected protocol standards and traffic flows e g extraneous packets that do not belong to established flows gratuitous or anomalous traffic patterns anomalous syntax or structure consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns e g monitor anomalies in use of files that do not normally initiate connections for respective protocol s references bright p 2011 february 15 anonymous speaks the inside story of the hbgary hack retrieved march 9 2017 microsoft 2022 march 22 dev 0537 criminal actor targeting organizations for data exfiltration and destruction retrieved march 23 2022 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|