Azure Add Owner To Application
Adds an owner to an Entra ID application registration, granting them management rights over the application.
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
View on MITRE ATT&CK →Adds an owner to an Entra ID application registration, granting them management rights over the application.
Adds an owner to a group, granting the ability to modify group membership for lateral movement.
Creates a new user account in Microsoft Entra ID.
Adds a permission to a Lambda function's resource-based policy, allowing specified principals to invoke the function.
Adds an IAM user to a specified group, granting the user all permissions attached to that group.
Records an administrator registering authentication methods (e.g., MFA) on behalf of another user in Entra ID.
Associates an IAM instance profile with an EC2 instance, granting the instance permissions defined by the profile's IAM role.
Attaches a managed IAM policy to a group, granting all group members the permissions defined in that policy.
Attaches a managed IAM policy to an IAM role, granting the role the permissions defined in that policy.
Attaches a managed IAM policy directly to an IAM user, granting them the permissions defined in that policy.
Allows an IAM user to change their own AWS Management Console login password.
Sets the IAM policy on a Compute Engine persistent disk, controlling which principals have access to it.
Changes the service account attached to a Compute Engine instance, enabling privilege escalation via service account swap.
Records an admin or user granting an Entra ID application permission to access resources via an OAuth 2.0 consent grant.
Creates an access entry for an EKS cluster, granting an IAM principal Kubernetes API access via EKS access management.
Creates a Glue development endpoint providing SSH access into the Glue VPC with the Glue service role.
Creates a new managed IAM policy that can be attached to users, groups, or roles to define permissions.
Creates a new version of an IAM managed policy, which can optionally be set as the default active version.
Creates a custom IAM role in GCP with a specified set of granular permissions.
Creates a CloudFormation stack by provisioning AWS resources defined in a specified template.
Creates a new IAM user in the AWS account for programmatic or console-based access.
Creates a virtual MFA device that can be associated with an IAM user for multi-factor authentication.
Re-enables a previously disabled GCP service account, restoring its ability to authenticate and make API calls.
Replaces the complete IAM policy for a GCP resource, controlling access for all principals.
Updates an existing custom IAM role, modifying its set of permitted permissions.
Modifies Key Vault access policies, potentially granting unauthorized access to secrets, keys, and certificates.
Assigns a user-assigned managed identity to an Azure resource, enabling it to authenticate to other Azure services.
Creates or updates an inline policy embedded directly in an IAM group.
Modifies a KMS key policy to grant cross-account access or expand key usage permissions.
Creates or updates an inline policy embedded directly in an IAM role.
Creates or updates an inline policy embedded directly in an IAM user.
Replaces the IAM instance profile associated with a running EC2 instance with a different one.
Resets an Entra ID user's password through an administrative action.
Sets the default version of an IAM managed policy, changing which version of the policy is active for all attached entities.
Changes the MFA or passwordless authentication methods registered for a user in Microsoft Entra ID.
Changes the status of an IAM user's access key between Active and Inactive.
Updates the trust policy of an IAM role, changing which principals are permitted to assume it.
Updates a Glue development endpoint, potentially injecting SSH public keys for unauthorized access.
Updates Lambda function configuration including environment variables, IAM role, or layers — used to inject credentials or swap execution context.
Updates the console login password for an IAM user.