kevmap

Techniques › T1199

T1199 Trusted Relationship

initial access — IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
7
analytics
2
Sigma rules tagged attack.t1199
1
KEV CVEs mapped here
<p>Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.</p><p>Organizations often grant elevated access to second or third-party external providers in order to allow them to manage internal systems as well as cloud-based environments. Some examples of these relationships include IT services contractors, managed security providers, infrastructure contractors (e.g. HVAC, elevators, physical security). The third-party provider's access may be intended to be limited to the infrastructure being maintained, but may exist on the same network as the rest of the enterprise. As such, Valid Accounts used by the other party for access to internal network systems may be compromised and used.</p><p>In Office 365 environments, organizations may grant Microsoft partners or resellers delegated administrator permissions. By compromising a partner or reseller account, an adversary may be able to leverage existing delegated administrator relationships or send new delegated administrator offers to clients in order to gain administrative control over the victim tenant.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2024-53704SonicWall SonicOS exploitation technique Mapped2025-02-18

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1199

Author: zendannyy · 2026-04-28 · logsource: product=okta service=okta · fe04b26b-0ac4-45d7-9404-4b9f16a440a9
Detects Okta session impersonation grant event where a user is granted the ability to impersonate another user's session. This event type "user.session.impersonation.grant" signifies that someone has been given temporary access to act on behalf of another user account. Threat actors may abuse this functionality to escalate privileges, access sensitive resources, or perform unauthorized actions while appearing to be the impersonated user. Legitimate use cases are typically limited to Okta support scenarios or authorized administrative troubleshooting.
Techniques: T1484.002T1199
Author: austinsonger · 2021-08-19 (modified 2022-10-09) · logsource: product=m365 service=threat_management · ff246f56-7f24-402a-baca-b86540e3925c
Detects when a Security Compliance Center reported a user who exceeded sending limits of the service policies and because of this has been restricted from sending email.
Techniques: T1199