T1087.004SubTechniquediscoveryagent-callable
T1087.004Cloud Account
Sub-technique of T1087
Platforms: Azure AD · Office 365 · SaaS · IaaS · Google Workspace
ATT&CK version: 14.1
What it is
Adversaries may attempt to get a listing of cloud accounts. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application.
With authenticated access there are several tools that can be used to find accounts. The <code>Get-MsolRoleMember</code> PowerShell cmdlet can be used to obtain account names given a role or permissions group in Office 365.(Citation: Microsoft msolrolemember)(Citation: GitHub Raindance) The Azure CLI (AZ CLI) also provides an interface to obtain user accounts with authenticated access to a domain. The command <code>az ad user list</code> will list all users within a domain.(Citation: Microsoft AZ CLI)(Citation: Black Hills Red Teaming MS AD Azure, 2018)
The AWS command <code>aws iam list-users</code> may be used to obtain a list of users in the current account while <code>aws iam list-roles</code> can obtain IAM roles that have a specified path prefix.(Citation: AWS List Roles)(Citation: AWS List Users) In GCP, <code>gcloud iam service-accounts list</code> and <code>gcloud projects get-iam-policy</code> may be used to obtain a listing of service accounts and users in a project.(Citation: Google Cloud - IAM Servie Accounts List API)
ATT&CK tactics· 1
References
- https://attack.mitre.org/techniques/T1087/004
- https://docs.microsoft.com/en-us/powershell/module/msonline/get-msolrolemember?view=azureadps-1.0
- https://github.com/True-Demon/raindance
- https://docs.microsoft.com/en-us/cli/azure/ad/user?view=azure-cli-latest
- https://www.blackhillsinfosec.com/red-teaming-microsoft-part-1-active-directory-leaks-via-azure/
- https://docs.aws.amazon.com/cli/latest/reference/iam/list-roles.html
- https://docs.aws.amazon.com/cli/latest/reference/iam/list-users.html
- https://cloud.google.com/sdk/gcloud/reference/iam/service-accounts/list