T1199 Trusted Relationship — Detection & Response
Adversaries may breach or otherwise leverage organisations who have access to intended targets. Access through trusted third-party relationships exploits an existing connection that may not be fully monitored or controlled by the target organisation — including managed service providers, IT contractors, software vendors, and technology partners with elevated access to the target environment.
Coverage at a glance
- Detections shipped
- 4
- Avg. verdict time
- < 5 min
- Data sources
- 4+
Threat context
How adversaries use T1199 Trusted Relationship — Detection & Response
Adversaries may breach or otherwise leverage organisations who have access to intended targets. Access through trusted third-party relationships exploits an existing connection that may not be fully monitored or controlled by the target organisation — including managed service providers, IT contractors, software vendors, and technology partners with elevated access to the target environment.
Third-party and supply chain compromises via trusted relationships are among the most damaging attack patterns. The SolarWinds attack is the canonical example: adversaries compromised a software vendor and used the trusted update mechanism to deploy SUNBURST across thousands of customer networks. MSSPs and IT outsourcing providers are also frequently targeted because compromising a single MSP credential grants access to dozens or hundreds of customer environments. Adversaries exploit the fact that connections from trusted sources often receive less scrutiny and may bypass conditional access policies.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| MSP Tool Agent Connecting from Unexpected Country An RMM tool agent (Kaseya, ConnectWise, TeamViewer) makes an outbound connection from a geography inconsistent with the contracted MSP. | High | Endpoint / EDR Logs |
| Third-Party SSO Session Without MFA A federated SSO session from a third-party organisation authenticates without MFA — potential indicator of compromised IdP or token theft. | High | Okta / Entra ID |
| New Cross-Account AWS Role Assumption AssumeRole event from an AWS account not previously seen assuming a role in the monitored environment — potential third-party account compromise. | Medium | AWS CloudTrail |
| Privileged Action Performed by Service Account Outside Maintenance Window A service account used by a third-party vendor performs privileged configuration changes outside the approved maintenance window. | High | Cloud Provider Logs |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1199 Trusted Relationship — Detection & Response: frequently asked questions
How is T1199 different from T1195 (Supply Chain Compromise)?
T1199 is about gaining initial access through a trusted relationship (MSP admin access, vendor VPN). T1195 involves compromising the supply chain of software or hardware before it reaches the target. SolarWinds involved both — T1195 for the software compromise and T1199 for the trusted delivery mechanism.
Can ManySignal detect when a vendor's RMM tool is being abused?
Yes. RMM tools (Kaseya VSA, ConnectWise, NinjaRMM) generate endpoint events when they execute commands. ManySignal detects unusual commands, connections to unexpected infrastructure, or RMM activity outside known maintenance windows.
How should third-party access be structured to minimise T1199 risk?
Use time-limited, JIT access with MFA. Avoid standing privileged accounts. Use separate IdP groups for vendor accounts so their activity is monitorable in isolation. Require vendors to operate from managed, compliant devices.
Does ManySignal alert on cross-tenant Azure Lighthouse delegations?
Yes. Azure Lighthouse delegated access appears in Azure Activity Logs. ManySignal monitors changes to Lighthouse delegations and flags actions taken by delegated MSP principals on non-maintenance-window schedules.
How does ManySignal handle MSP environments where one tenant manages many customers?
ManySignal's multi-tenancy architecture is designed for MSP deployments. Each customer tenant is monitored independently with cross-tenant correlation for identifying compromised MSP credentials used across multiple customers.
Can ManySignal detect when a software vendor's update mechanism is used maliciously?
Software update execution events are captured by endpoint agents. ManySignal detects when an update process spawns unexpected child processes, makes unusual network connections, or modifies files in unexpected locations.
What is the typical dwell time for T1199 attacks?
T1199 attacks via MSP channels often have very long dwell times — months to years — because activity from trusted remote management tools receives less scrutiny. ManySignal's baseline behavioural models detect deviations from the established vendor access pattern even after long periods.
Should third-party accounts be monitored differently than employee accounts?
Yes. Third-party accounts should be tagged in ManySignal with vendor context. Detection thresholds can be configured differently — for example, any privileged action by a vendor account outside business hours triggers a High alert regardless of other context.
What OAuth scopes should vendor applications be granted?
Grant the minimum necessary OAuth scopes and review regularly. ManySignal alerts on vendor OAuth applications that request scope expansions or that access resources beyond their declared purpose.
How does ManySignal handle vendors using shared service accounts?
Shared service accounts are a significant risk — individual attribution is impossible. ManySignal detects concurrent sessions from the same service account from different IPs as a potential account sharing or compromise indicator.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.