Valid Accounts: Cloud Accounts
The attacker uses valid credentials obtained through the reset token to access user accounts.
Metadata
- Severity: medium
- Slug: valid-accounts-cloud-accounts
MITRE
- T1098.001: Account Manipulation: Additional Cloud Credentials
- T1078.004: Valid Accounts: Cloud Accounts
- T1070.003: Indicator Removal: Clear Command History