M ManySignal
T1078 MITRE ATT&CK

T1078 Valid Accounts — Detection & Response

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services.

Coverage at a glance

Detections shipped
5
Avg. verdict time
< 5 min
Data sources
4+

Threat context

How adversaries use T1078 Valid Accounts — Detection & Response

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services.

Valid account abuse is the most common initial access vector in cloud breaches. Attackers obtain credentials through phishing, credential stuffing, password spraying, or purchasing from dark web markets. Once in possession of valid credentials, adversaries can authenticate as the legitimate user, operate within normal policy boundaries, and generate minimal anomalous signals — making detection reliant on behavioural analysis rather than signature matching. In cloud environments, stolen IAM credentials enable lateral movement across services without touching endpoint telemetry.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

Impossible Travel — Authentication from geographically impossible locations

Two authentications from the same user within a time window that requires physically impossible travel speed.

High Okta / Entra ID

New Country First-Use — Initial sign-in from a country with no prior history

User authenticates from a country never previously observed in their sign-in history.

Medium Okta / Entra ID / AWS CloudTrail

Credential Stuffing Spike — High-volume failed logins followed by success

Pattern of many rapid failed authentications for multiple users followed by one success, indicating automated credential stuffing.

High Okta / Entra ID

AWS Console Sign-In Without MFA — Root or IAM user sign-in without MFA

Console sign-in with valid credentials but without MFA, violating security baseline.

Critical AWS CloudTrail

Dormant Account Reactivation — Sign-in from account inactive for 90+ days

A user account that has been dormant suddenly authenticates, potentially indicating compromised credentials.

Medium Okta / Active Directory

T1078 Valid Accounts — Detection & Response: frequently asked questions

How does ManySignal detect T1078 when credentials are legitimately shared?

ManySignal builds per-user behavioural baselines covering device, IP subnet, ASN, time-of-day, and geographic patterns. Even with shared credentials, deviations from the established baseline generate anomaly signals that are corroborated with other contextual signals before generating an alert.

Does T1078 apply to service accounts?

Yes. T1078.003 (Local Accounts) and T1078.004 (Cloud Accounts) cover service account abuse. ManySignal monitors service account behaviour separately from interactive user behaviour, with tighter baselines since service accounts should be highly predictable.

What is the difference between T1078 and credential access techniques?

T1078 covers the use of already-obtained valid credentials. Credential Access (TA0006) covers how adversaries acquire those credentials — through techniques like T1110 (Brute Force), T1539 (Steal Web Session Cookie), or T1552 (Unsecured Credentials).

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.