+User Account Management

User Account Management

User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures: Enforcing the Principle of Least Privilege - Implementation: Assign users only the minimum permissions required to perform their job functions. Regularly audit accounts to ensure no excess permissions are granted. - Use Case: Reduces the risk of privilege escalation by ensuring accounts cannot perform unauthorized actions. Implementing Strong Password Policies - Implementation: Enforce password complexity requirements (e.g., length, character types). Require password expiration every 90 days and disallow password reuse. - Use Case: Prevents adversaries from gaining unauthorized access through password guessing or brute force attacks. Managing Dormant and Orphaned Accounts - Implementation: Implement automated workflows to disable accounts after a set period of inactivity (e.g., 30 days). Remove orphaned accounts (e.g., accounts without an assigned owner) during regular account audits. - Use Case: Eliminates dormant accounts that could be exploited by attackers. Account Lockout Policies - Implementation: Configure account lockout thresholds (e.g., lock accounts after five failed login attempts). Set lockout durations to a minimum of 15 minutes. - Use Case: Mitigates automated attack techniques that rely on repeated login attempts. Multi-Factor Authentication (MFA) for High-Risk Accounts - Implementation: Require MFA for all administrative accounts and high-risk users. Use MFA mechanisms like hardware tokens, authenticator apps, or biometrics. - Use Case: Prevents unauthorized access, even if credentials are stolen. Restricting Interactive Logins - Implementation: Restrict interactive logins for privileged accounts to specific secure systems or management consoles. Use group policies to enforce logon restrictions. - Use Case: Protects sensitive accounts from misuse or exploitation. *Tools for Implementation* Built-in Tools: - Microsoft Active Directory (AD): Centralized account management and RBAC enforcement. - Group Policy Object (GPO): Enforce password policies, logon restrictions, and account lockout policies. Identity and Access Management (IAM) Tools: - Okta: Centralized user provisioning, MFA, and SSO integration. - Microsoft Azure Active Directory: Provides advanced account lifecycle management, role-based access, and conditional access policies. Privileged Account Management (PAM): - CyberArk, BeyondTrust, Thycotic: Manage and monitor privileged account usage, enforce session recording, and JIT access.

1. Übersicht

Bezeichnung Standard

1.1 Referenzen

1.2 Identifizierte Anforderungen

1.3 Related Regulations

2. Identifizierte Anforderungen

Anforderungen
Source Anforderung

3. Related Regulations

Regulations
Source Regulierung

Linked Issues

Issuelinks
Linktyp Issue
is related to Mitigations
blocks Cloud Infrastructure Discovery
blocks Poisoned Pipeline Execution
blocks Domain Accounts
blocks Create or Modify System Process
blocks Network Sniffing
blocks Modify Cloud Compute Infrastructure
blocks Software Deployment Tools
blocks Direct Cloud VM Connections
blocks Services File Permissions Weakness
blocks Customer Relationship Management Software
blocks Modify Cloud Compute Configurations
blocks Disable or Modify Windows Event Log
blocks SSH Authorized Keys
blocks Cloud Storage Object Discovery
blocks Disable or Modify Tools
blocks Scheduled Task/Job
blocks Multi-Factor Authentication
blocks Data from Cloud Storage
blocks Masquerading
blocks Deploy Container
blocks BITS Jobs
blocks Transfer Data to Cloud Account
blocks Conditional Access Policies
blocks Spearphishing via Service
blocks Windows Management Instrumentation Event Subscription
blocks Shortcut Modification
blocks Delete Cloud Instance
blocks Access Token Manipulation
blocks Network Device Firewall
blocks Launch Daemon
blocks Windows Management Instrumentation
blocks Token Impersonation/Theft
blocks Spearphishing Attachment
blocks Container Administration Command
blocks Pass the Ticket
blocks Log Enumeration
blocks Hijack Execution Flow
blocks Valid Accounts
blocks Additional Cloud Credentials
blocks Container Orchestration Job
blocks Group Policy Modification
blocks Kernel Modules and Extensions
blocks RDP Hijacking
blocks Account Manipulation
blocks System Services
blocks Disable or Modify System Firewall
blocks Modify Cloud Resource Hierarchy
blocks Sharepoint
blocks Systemd Service
blocks Lifecycle-Triggered Deletion
blocks Remote Services
blocks Disable or Modify Linux Audit System Log
blocks Pass the Hash
blocks Password Managers
blocks Domain or Tenant Policy Modification
blocks Abuse Elevation Control Mechanism
blocks Local Accounts
blocks XDG Autostart Entries
blocks Cloud Firewall
blocks Data from Information Repositories
blocks ESXi Administration Command
blocks Remote Desktop Protocol
blocks Trust Modification
blocks Create Snapshot
blocks SAML Tokens
blocks Create Process with Token
blocks Scheduled Task
blocks Spearphishing Link
blocks Credentials from Web Browsers
blocks Trusted Relationship
blocks Credential Stuffing
blocks Browser Session Hijacking
blocks Supply Chain Compromise
blocks SSH
blocks Disable or Modify Cloud Log
blocks Make and Impersonate Token
blocks Service Stop
blocks Financial Theft
blocks Brute Force
blocks Data Destruction
blocks Temporary Elevated Cloud Access
blocks Cloud Service Dashboard
blocks Account Discovery
blocks Use Alternate Authentication Material
blocks At
blocks Cron
blocks Winlogon Helper DLL
blocks Systemctl
blocks Web Shell
blocks Direct Volume Access
blocks Container API
blocks Container Service
blocks Serverless Execution
blocks Code Repositories
blocks Container and Resource Discovery
blocks Print Processors
blocks Windows Service
blocks Databases
blocks Modify Authentication Process
blocks Steal Application Access Token
blocks Inhibit System Recovery
blocks Masquerade Account Name
blocks Systemd Timers
blocks Executable Installer File Permissions Weakness
blocks Remote Service Session Hijacking
blocks Launchctl
blocks Confluence
blocks Create Cloud Instance
blocks Cloud Account
blocks Server Software Component
blocks Forge Web Credentials
blocks Windows Host Firewall
blocks Exfiltration Over Alternative Protocol
blocks Network Device CLI
blocks Additional Container Cluster Roles
blocks Additional Cloud Roles
blocks Traffic Duplication
blocks COR_PROFILER
blocks Cloud Accounts
  • MITREATTACK -

    © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. https://attack.mitre.org/

    Terms of Use

    LICENSE

    The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

    "© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation."

    DISCLAIMERS

    MITRE does not claim ATT&CK enumerates all possibilities for the types of actions and behaviors documented as part of its adversary model and framework of techniques. Using the information contained within ATT&CK to address or cover full categories of techniques will not guarantee full defensive coverage as there may be undisclosed techniques or variations on existing techniques not documented by ATT&CK.

    ALL DOCUMENTS AND THE INFORMATION CONTAINED THEREIN ARE PROVIDED ON AN "AS IS" BASIS AND THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE MITRE CORPORATION, ITS BOARD OF TRUSTEES, OFFICERS, AGENTS, AND EMPLOYEES, DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION THEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.

    See our FAQ for more information on how to use and represent the ATT&CK name.

Impressum Deutsch Englisch