Skip to content
← LibraryTechnique entry
T1098Persistence

Account Manipulation

Modify accounts to maintain access.

§ Where this technique fits

T1098 is catalogued under the Persistence tactic of the offensive-security kill-chain. It appears in 6 approved dossiers in the registry, typically at step 4.7 on average.

Authoritative reference: attack.mitre.org/techniques/T1098/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Valid Accounts
    T1078 · Initial Access
    seen 2×
  2. 02
    Azure RBAC Owner Assignment
    C-AZ-RBAC-OWNER · Privilege Escalation
    seen 1×
  3. 03
    ESXi Mass-Encrypt Ransomware
    HV-ESXI-RANSOM · Impact
    seen 1×
  4. 04
    Exchange Web Services (EWS) Exfil
    M365-EWS-EXFIL · Collection
    seen 1×
  5. 05
    Exfiltration Over C2 Channel
    T1041 · Exfiltration
    seen 1×