T1078 Valid Accounts — Detection & Response
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services.
Coverage at a glance
- Detections shipped
- 5
- Avg. verdict time
- < 5 min
- Data sources
- 4+
Threat context
How adversaries use T1078 Valid Accounts — Detection & Response
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services.
Valid account abuse is the most common initial access vector in cloud breaches. Attackers obtain credentials through phishing, credential stuffing, password spraying, or purchasing from dark web markets. Once in possession of valid credentials, adversaries can authenticate as the legitimate user, operate within normal policy boundaries, and generate minimal anomalous signals — making detection reliant on behavioural analysis rather than signature matching. In cloud environments, stolen IAM credentials enable lateral movement across services without touching endpoint telemetry.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| Impossible Travel — Authentication from geographically impossible locations Two authentications from the same user within a time window that requires physically impossible travel speed. | High | Okta / Entra ID |
| New Country First-Use — Initial sign-in from a country with no prior history User authenticates from a country never previously observed in their sign-in history. | Medium | Okta / Entra ID / AWS CloudTrail |
| Credential Stuffing Spike — High-volume failed logins followed by success Pattern of many rapid failed authentications for multiple users followed by one success, indicating automated credential stuffing. | High | Okta / Entra ID |
| AWS Console Sign-In Without MFA — Root or IAM user sign-in without MFA Console sign-in with valid credentials but without MFA, violating security baseline. | Critical | AWS CloudTrail |
| Dormant Account Reactivation — Sign-in from account inactive for 90+ days A user account that has been dormant suddenly authenticates, potentially indicating compromised credentials. | Medium | Okta / Active Directory |
Related techniques and tactics
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1539 Steal Web Session Cookie — Detection & Response
ATT&CK Technique
T1078 Valid Accounts — Detection & Response: frequently asked questions
How does ManySignal detect T1078 when credentials are legitimately shared?
ManySignal builds per-user behavioural baselines covering device, IP subnet, ASN, time-of-day, and geographic patterns. Even with shared credentials, deviations from the established baseline generate anomaly signals that are corroborated with other contextual signals before generating an alert.
Does T1078 apply to service accounts?
Yes. T1078.003 (Local Accounts) and T1078.004 (Cloud Accounts) cover service account abuse. ManySignal monitors service account behaviour separately from interactive user behaviour, with tighter baselines since service accounts should be highly predictable.
What is the difference between T1078 and credential access techniques?
T1078 covers the use of already-obtained valid credentials. Credential Access (TA0006) covers how adversaries acquire those credentials — through techniques like T1110 (Brute Force), T1539 (Steal Web Session Cookie), or T1552 (Unsecured Credentials).
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.