What is account pivoting?¶
The practical answer¶
Account pivoting is the use of one compromised or authorised account to obtain access to another account, service or system.
The key evidential caution¶
The dangerous assumption is that the first compromised account remains the only identity used throughout the incident.
It may not.
An offender may use one account to:
Key points¶
- reset another account
- approve access
- create a new user
- change group membership
- grant application permissions
- access stored credentials
- impersonate another user
- reach a more privileged system
What investigators should establish¶
Investigators should identify:
Key points¶
- the starting account
- the target account
- the action that linked them
- the privilege or access gained
- the time
- the system or provider involved
- later use of the target account
Relevant evidence¶
Relevant evidence may include password-reset events, administrative actions, consent records, directory changes, mailbox activity, session logs and provider audit data.
Evidential limits¶
Do not assume the target account holder was involved.
Their account may have been taken over through the first account.
Likewise, the starting account holder may also be a victim.
Account pivoting can create a chain in which later activity appears to come from several legitimate identities.
Account pivoting may also cross organisational boundaries, such as moving from a compromised supplier account into a customer service. Preserve tenant, directory and provider identifiers so the chain is not reduced to similar display names.
That distinction is essential where several organisations use the same platform.
Record the provider and tenant boundary.
Operational takeaway¶
Trace the chain from one account to the next, preserve the linking administrative or recovery events and keep each account holder separate from the actor controlling it.