Skip to content
← LibraryTechnique entry
T1078Initial Access

Valid Accounts

Obtain and abuse credentials of existing accounts.

§ Where this technique fits

T1078 is catalogued under the Initial Access tactic of the offensive-security kill-chain. It appears in 100 approved dossiers in the registry, typically at step 2 on average.

Authoritative reference: attack.mitre.org/techniques/T1078/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    BloodHound / SharpHound Enumeration
    AD-BLOODHOUND · Discovery
    seen 8×
  2. 02
    Exfiltration Over C2 Channel
    T1041 · Exfiltration
    seen 8×
  3. 03
    Account Discovery
    T1087 · Discovery
    seen 6×
  4. 04
    Exchange Web Services (EWS) Exfil
    M365-EWS-EXFIL · Collection
    seen 5×
  5. 05
    Internal Nmap Sweep
    N-NMAP-INTERNAL · Discovery
    seen 5×
  6. 06
    Unsecured Credentials
    T1552 · Credential Access
    seen 3×
  7. 07
    ARP Spoofing / Cache Poisoning
    N-ARP-SPOOF · Credential Access
    seen 2×
  8. 08
    Account Manipulation
    T1098 · Persistence
    seen 2×