LoFP
/
t1098.003
t1098.003
Title
Tags
administrator roles could be assigned to users or group by other admin users.
t1098
t1098.003
okta
sigma
legitimate administrative activities changing the access levels for an application
t1098
t1098.003
gcp
sigma
pim (privileged identity management) generates this event each time 'eligible role' is enabled.
t1078
t1098
t1098.003
azure
sigma
valid change
t1003
t1098
t1098.003
azure
sigma
validate the actor if permitted to access the repo.
t1098
t1098.001
t1098.003
t1213
t1213.003
github
sigma
validate the multifactor authentication changes.
t1098
t1098.001
t1098.003
t1213
t1213.003
github
sigma
when the permission is legitimately needed for the app
t1098
t1098.003
t1528
azure
sigma