+Privileged Account Management

Privileged Account Management

Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures: Account Permissions and Roles: - Implement RBAC and least privilege principles to allocate permissions securely. - Use tools like Active Directory Group Policies to enforce access restrictions. Credential Security: - Deploy password vaulting tools like CyberArk, HashiCorp Vault, or KeePass for secure storage and rotation of credentials. - Enforce password policies for complexity, uniqueness, and expiration using tools like Microsoft Group Policy Objects (GPO). Multi-Factor Authentication (MFA): - Enforce MFA for all privileged accounts using Duo Security, Okta, or Microsoft Azure AD MFA. Privileged Access Management (PAM): - Use PAM solutions like CyberArk, BeyondTrust, or Thycotic to manage, monitor, and audit privileged access. Auditing and Monitoring: - Integrate activity monitoring into your SIEM (e.g., Splunk or QRadar) to detect and alert on anomalous privileged account usage. Just-In-Time Access: - Deploy JIT solutions like Azure Privileged Identity Management (PIM) or configure ephemeral roles in AWS and GCP to grant time-limited elevated permissions. *Tools for Implementation* Privileged Access Management (PAM): - CyberArk, BeyondTrust, Thycotic, HashiCorp Vault. Credential Management: - Microsoft LAPS (Local Admin Password Solution), Password Safe, HashiCorp Vault, KeePass. Multi-Factor Authentication: - Duo Security, Okta, Microsoft Azure MFA, Google Authenticator. Linux Privilege Management: - sudo configuration, SELinux, AppArmor. Just-In-Time Access: - Azure Privileged Identity Management (PIM), AWS IAM Roles with session constraints, GCP Identity-Aware Proxy.

1. Übersicht

Bezeichnung Standard

1.1 Referenzen

1.2 Identifizierte Anforderungen

1.3 Related Regulations

2. Identifizierte Anforderungen

Anforderungen
Source Anforderung

3. Related Regulations

Regulations
Source Regulierung

Linked Issues

Issuelinks
Linktyp Issue
is related to Mitigations
blocks Scheduled Task
blocks Pass the Ticket
blocks Cloud Secrets Management Stores
blocks IIS Components
blocks Reversible Encryption
blocks Credentials from Password Stores
blocks Service Execution
blocks Transport Agent
blocks Windows Management Instrumentation
blocks Credentials in Registry
blocks Additional Cloud Roles
blocks Windows Permissions
blocks Pluggable Authentication Modules
blocks Windows Remote Management
blocks System Services
blocks Network Boundary Bridging
blocks /etc/passwd and /etc/shadow
blocks Software Deployment Tools
blocks Create or Modify System Process
blocks Code Signing Policy Modification
blocks Domain or Tenant Policy Modification
blocks Kernel Modules and Extensions
blocks Make and Impersonate Token
blocks System Firmware
blocks Domain Accounts
blocks Exploit Public-Facing Application
blocks Cloud Accounts
blocks Local Accounts
blocks Safe Mode Boot
blocks Silver Ticket
blocks Build Image on Host
blocks Trust Modification
blocks Additional Email Delegate Permissions
blocks Container CLI/API
blocks NTDS
blocks Linux and Mac Permissions
blocks TFTP Boot
blocks Create Process with Token
blocks Forge Web Credentials
blocks Component Object Model
blocks Escape to Host
blocks Cloud Account
blocks System Binary Proxy Execution
blocks Use Alternate Authentication Material
blocks Container Orchestration Job
blocks Subvert Trust Controls
blocks Security Account Manager
blocks Process Injection
blocks Abuse Elevation Control Mechanism
blocks Domain Controller Authentication
blocks Container API
blocks Valid Accounts
blocks Additional Cloud Credentials
blocks Implant Internal Image
blocks Scheduled Task/Job
blocks Bypass User Account Control
blocks SMB/Windows Admin Shares
blocks TCC Manipulation
blocks Bootkit
blocks File and Directory Permissions Modification
blocks Container Administration Command
blocks Exploitation of Remote Services
blocks Account Manipulation
blocks OS Credential Dumping
blocks Event Triggered Execution
blocks Patch System Image
blocks Golden Ticket
blocks Hybrid Identity
blocks Windows Management Instrumentation Event Subscription
blocks LSASS Memory
blocks Command and Scripting Interpreter
blocks Web Portal Capture
blocks Pass the Hash
blocks Downgrade System Image
blocks Pre-OS Boot
blocks Create Account
blocks Firmware Corruption
blocks SAML Tokens
blocks RDP Hijacking
blocks Access Token Manipulation
blocks Systemd Service
blocks Local Account
blocks Cached Domain Credentials
blocks Network Device Authentication
blocks LSA Secrets
blocks Cloud API
blocks Inter-Process Communication
blocks SQL Stored Procedures
blocks Ptrace System Calls
blocks Network Address Translation Traversal
blocks Proc Filesystem
blocks Token Impersonation/Theft
blocks DCSync
blocks Modify Authentication Process
blocks Cloud Services
blocks Modify System Image
blocks At
blocks Unsecured Credentials
blocks Remote Service Session Hijacking
blocks SSH Hijacking
blocks PowerShell
blocks Remote Desktop Protocol
blocks Systemd Timers
blocks Domain Account
blocks Distributed Component Object Model
blocks Network Device CLI
blocks Msiexec
blocks Server Software Component
blocks Sudo and Sudo Caching
blocks Cloud Administration Command
blocks Kerberoasting
blocks Steal or Forge Kerberos Tickets
  • MITREATTACK -

    © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. https://attack.mitre.org/

    Terms of Use

    LICENSE

    The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

    "© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation."

    DISCLAIMERS

    MITRE does not claim ATT&CK enumerates all possibilities for the types of actions and behaviors documented as part of its adversary model and framework of techniques. Using the information contained within ATT&CK to address or cover full categories of techniques will not guarantee full defensive coverage as there may be undisclosed techniques or variations on existing techniques not documented by ATT&CK.

    ALL DOCUMENTS AND THE INFORMATION CONTAINED THEREIN ARE PROVIDED ON AN "AS IS" BASIS AND THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE MITRE CORPORATION, ITS BOARD OF TRUSTEES, OFFICERS, AGENTS, AND EMPLOYEES, DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION THEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.

    See our FAQ for more information on how to use and represent the ATT&CK name.

Impressum Deutsch Englisch