MITRE ATT&CK CoA - T1078 - Valid Accounts

This playbook Remediates the Valid Accounts technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. ***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs). Techniques Handled: - T1078: Valid Accounts Kill Chain phases: - Defense Evasion - Persistence - Privilege Escalation - Initial Access MITRE ATT&CK Description: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence. The overlap of permissions for local, domain, and cloud accounts across a network of systems is of concern because the adversary may be able to pivot across accounts and systems to reach a high level of access (i.e., domain or enterprise administrator) to bypass access controls set within the enterprise. Possible playbook uses: - The playbook can be used independently to handle and remediate the specific technique. - The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase. - The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.

MITRE ATT&CK - Courses of Action · 11 tasks · 3 inputs · 1 output

Details

IDMITRE ATT&CK CoA - T1078 - Valid Accounts
From Version6.5.0
Tasks11

README

This playbook Remediates the Valid Accounts technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.

***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:

  • T1078: Valid Accounts

Kill Chain phases:

  • Defense Evasion
  • Persistence
  • Privilege Escalation
  • Initial Access

MITRE ATT&CK Description:

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

The overlap of permissions for local, domain, and cloud accounts across a network of systems is of concern because the adversary may be able to pivot across accounts and systems to reach a high level of access (i.e., domain or enterprise administrator) to bypass access controls set within the enterprise.

Possible playbook uses:

  • The playbook can be used independently to handle and remediate the specific technique.
  • The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
  • The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • access_investigation_-_generic
  • PAN-OS - Enforce URL Filtering Best Practices Profile

Integrations

This playbook does not use any integrations.

Scripts

  • SetGridField
  • Set

Commands

This playbook does not use any commands.

Playbook Inputs


Name Description Default Value Required
pre_post Rules location. Can be ‘pre-rulebase’ or ‘post-rulebase’. Mandatory for Panorama instances.   Optional
device-group The device group for which to return addresses (Panorama instances).   Optional
tag Tag for which to filter the results.   Optional

Playbook Outputs


Path Description Type
Handled.Techniques The technique handled in this playbook unknown

Playbook Image


MITRE ATT&CK CoA - T1078 - Valid Accounts

Inputs

  • pre_post — Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances.
  • device-group — The device group for which to return addresses (Panorama instances).
  • tag — Tag for which to filter the results.

Outputs

  • Handled.Techniques — The technique handled in this playbook

Flowchart

yes Start Start Manual - NGFW - Configure Multi-Factor Authentication Manual - NGFW - Configure... access_investigation_-_generic - access_investigation_-_generic access_investigation_-_ge... access_investigation_-_generic Done Done PAN-OS - Enforce URL Filtering Best Practices Profile - PAN-OS - Enforce URL Filtering Best Practices Profile PAN-OS - Enforce URL Filt... PAN-OS - Enforce URL Filterin... Enable Credential Phishing protection Enable Credential Phishin... Would you like to use "Access Investigation - Generic" playbook? Would you like to use "Ac... Set technique handled Set technique handled Provide details for "Access Investigation - Generic" playbook Provide details for "Acce... Deploy Cortex XSOAR Playbook – Access Investigation Deploy Cortex XSOAR Playb... Set grid field Set grid field
description: "This playbook Remediates the Valid Accounts technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.\n \n***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).\nTechniques Handled:\n- T1078: Valid Accounts\n\nKill Chain phases:\n- Defense Evasion\n- Persistence\n- Privilege Escalation\n- Initial Access\n\nMITRE ATT&CK Description:\n\nAdversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.\n\nThe overlap of permissions for local, domain, and cloud accounts across a network of systems is of concern because the adversary may be able to pivot across accounts and systems to reach a high level of access (i.e., domain or enterprise administrator) to bypass access controls set within the enterprise.\n\nPossible playbook uses:\n- The playbook can be used independently to handle and remediate the specific technique.\n- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.\n- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.\n"
id: MITRE ATT&CK CoA - T1078 - Valid Accounts
inputs:
- description: Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances.
  key: pre_post
  playbookInputQuery:
  required: false
  value: {}
- description: The device group for which to return addresses (Panorama instances).
  key: device-group
  playbookInputQuery:
  required: false
  value: {}
- description: Tag for which to filter the results.
  key: tag
  playbookInputQuery:
  required: false
  value: {}
name: MITRE ATT&CK CoA - T1078 - Valid Accounts
outputs:
- contextPath: Handled.Techniques
  description: The technique handled in this playbook
  type: unknown
starttaskid: "0"
tasks:
  "0":
    id: "0"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "1"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 8d617e05-aee9-453b-8390-e9c39a3e677d
      iscommand: false
      name: ""
      version: -1
      description: ''
    taskid: 8d617e05-aee9-453b-8390-e9c39a3e677d
    timertriggers: []
    type: start
    view: |-
      {
        "position": {
          "x": 265,
          "y": 50
        }
      }
  "1":
    id: "1"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "11"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Configure Multi-Factor Authentication in PAN-OS.
      id: a06e9baa-2786-4171-87d2-c2686e3abe6c
      iscommand: false
      name: Manual - NGFW - Configure Multi-Factor Authentication
      type: regular
      version: -1
    taskid: a06e9baa-2786-4171-87d2-c2686e3abe6c
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 265,
          "y": 195
        }
      }
  "8":
    id: "8"
    ignoreworker: false
    loop:
      exitCondition: ""
      iscommand: false
      max: 100
      wait: 1
    nexttasks:
      '#none#':
      - "13"
    note: false
    quietmode: 0
    scriptarguments:
      DstIP:
        complex:
          accessor: "1"
          root: Provide details for "Access Investigation - Generic" playbook.Answers
      OnCall:
        complex:
          accessor: "4"
          root: Provide details for "Access Investigation - Generic" playbook.Answers
      Role:
        complex:
          accessor: "3"
          root: Provide details for "Access Investigation - Generic" playbook.Answers
      SrcIP:
        complex:
          accessor: "0"
          root: Provide details for "Access Investigation - Generic" playbook.Answers
      Username:
        complex:
          accessor: "2"
          root: Provide details for "Access Investigation - Generic" playbook.Answers
    separatecontext: true
    skipunavailable: true
    task:
      brand: ""
      description: |-
        This playbook investigates an access incident by gathering user and IP information.

        The playbook then interacts with the user that triggered the incident to confirm whether or not they initiated the access action.
      id: c8d38952-0652-4393-81e1-731cad6d4b58
      iscommand: false
      name: access_investigation_-_generic
      playbookId: access_investigation_-_generic
      type: playbook
      version: -1
    taskid: c8d38952-0652-4393-81e1-731cad6d4b58
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 690,
          "y": 1190
        }
      }
  "9":
    id: "9"
    ignoreworker: false
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 0790b89a-c34f-4c24-8aab-1c77007d838c
      iscommand: false
      name: Done
      type: title
      version: -1
      description: ''
    taskid: 0790b89a-c34f-4c24-8aab-1c77007d838c
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 265,
          "y": 1725
        }
      }
  "10":
    id: "10"
    ignoreworker: false
    loop:
      exitCondition: ""
      iscommand: false
      max: 100
      wait: 1
    nexttasks:
      '#none#':
      - "12"
    note: false
    quietmode: 0
    scriptarguments:
      ApplyToRule:
        complex:
          root: inputs.ApplyToRule
      device-group:
        complex:
          root: inputs.device-group
      pre-post-rulebase:
        complex:
          root: inputs.pre_post
      rule_name:
        complex:
          root: inputs.rule_name
      tag:
        complex:
          root: inputs.tag
    separatecontext: true
    skipunavailable: false
    task:
      brand: ""
      id: c92280dd-54d0-4158-8933-4e85e211801f
      iscommand: false
      name: PAN-OS - Enforce URL Filtering Best Practices Profile
      playbookId: PAN-OS - Enforce URL Filtering Best Practices Profile
      type: playbook
      version: -1
      description: ''
    taskid: c92280dd-54d0-4158-8933-4e85e211801f
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 265,
          "y": 515
        }
      }
  "11":
    id: "11"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "10"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 2c5d7812-20fd-4e4c-801c-58d35fdaeb1a
      iscommand: false
      name: Enable Credential Phishing protection
      type: title
      version: -1
      description: ''
    taskid: 2c5d7812-20fd-4e4c-801c-58d35fdaeb1a
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 265,
          "y": 370
        }
      }
  "12":
    id: "12"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "13"
      "yes":
      - "15"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Would you like to use "Access Investigation - Generic" playbook?
      id: 94e731cd-12fd-48c4-80b7-0cfd0aa93d9d
      iscommand: false
      name: Would you like to use "Access Investigation - Generic" playbook?
      type: condition
      version: -1
    taskid: 94e731cd-12fd-48c4-80b7-0cfd0aa93d9d
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 265,
          "y": 690
        }
      }
  "13":
    id: "13"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "16"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: Handled.Techniques
      stringify: {}
      value:
        simple: T1078
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: 662b529b-6817-4dee-884b-9acf96756679
      iscommand: false
      name: Set technique handled
      script: Set
      type: regular
      version: -1
    taskid: 662b529b-6817-4dee-884b-9acf96756679
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 265,
          "y": 1360
        }
      }
  "14":
    form:
      description: ""
      expired: false
      questions:
      - defaultrows: []
        fieldassociated: ""
        gridcolumns: []
        id: "0"
        label: ""
        labelarg:
          simple: SrcIP
        options: []
        optionsarg: []
        placeholder: ""
        readonly: false
        required: true
        tooltip: ""
        type: shortText
      - defaultrows: []
        fieldassociated: ""
        gridcolumns: []
        id: "1"
        label: ""
        labelarg:
          simple: DstIP
        options: []
        optionsarg: []
        placeholder: ""
        readonly: false
        required: true
        tooltip: ""
        type: shortText
      - defaultrows: []
        fieldassociated: ""
        gridcolumns: []
        id: "2"
        label: ""
        labelarg:
          simple: Username
        options: []
        optionsarg: []
        placeholder: ""
        readonly: false
        required: true
        tooltip: ""
        type: shortText
      - defaultrows: []
        fieldassociated: ""
        gridcolumns: []
        id: "3"
        label: ""
        labelarg:
          simple: Role
        options: []
        optionsarg: []
        placeholder: Administrator
        readonly: false
        required: false
        tooltip: ""
        type: shortText
      - defaultrows: []
        fieldassociated: ""
        gridcolumns: []
        id: "4"
        label: ""
        labelarg:
          simple: OnCall
        options: []
        optionsarg: []
        placeholder: "false"
        readonly: false
        required: false
        tooltip: ""
        type: shortText
      sender: ""
      title: Provide details for "Access Investigation - Generic" playbook
      totalanswers: 0
    id: "14"
    ignoreworker: false
    message:
      bcc:
      body:
        simple: Provide details for "Access Investigation - Generic" playbook
      cc:
      format: ""
      methods: []
      subject:
      timings:
        completeafterreplies: 1
        retriescount: 2
        retriesinterval: 360
      to:
    nexttasks:
      '#none#':
      - "8"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Provide details for "Access Investigation - Generic" playbook.
      id: f9925278-063c-43ed-8cba-05594138a656
      iscommand: false
      name: Provide details for "Access Investigation - Generic" playbook
      type: collection
      version: -1
    taskid: f9925278-063c-43ed-8cba-05594138a656
    timertriggers: []
    type: collection
    view: |-
      {
        "position": {
          "x": 690,
          "y": 1010
        }
      }
  "15":
    id: "15"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "14"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: f18902cb-dd15-4a72-8bfa-37e799417053
      iscommand: false
      name: Deploy Cortex XSOAR Playbook – Access Investigation
      type: title
      version: -1
      description: ''
    taskid: f18902cb-dd15-4a72-8bfa-37e799417053
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 690,
          "y": 860
        }
      }
  "16":
    continueonerror: true
    id: "16"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "9"
    note: false
    quietmode: 0
    scriptarguments:
      columns:
        simple: technique
      context_path:
        simple: Handled.Techniques
      grid_id:
        simple: handledtechniques
      keys: {}
      overwrite: {}
      sort_by: {}
      unpack_nested_elements: {}
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Creates a Grid table from items or key-value pairs.
      id: e30cae42-441d-42bc-81f8-5b94786b4b4f
      iscommand: false
      name: Set grid field
      script: SetGridField
      type: regular
      version: -1
    taskid: e30cae42-441d-42bc-81f8-5b94786b4b4f
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 265,
          "y": 1540
        }
      }
version: -1
view: |-
  {
    "linkLabelsPosition": {
      "12_13_#default#": 0.47
    },
    "paper": {
      "dimensions": {
        "height": 1740,
        "width": 805,
        "x": 265,
        "y": 50
      }
    }
  }
tests:
- No tests (auto formatted)
fromversion: 6.5.0