Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is account pivoting?

Account pivoting uses access to one identity to obtain or control another account, service or system. The first compromised account may only be the start of a chain of apparently legitimate identities.

Find the linking action

Identify the starting and target accounts, then preserve the event that connects them: password reset, new-user creation, role change, consent grant, recovery change, impersonation or access to stored credentials. Directory, mailbox, provider and session audits can show the time, system and authority used.

Follow the target identity into its first authentication and later actions. Creation or reset proves changed access, not that the new route was used.

Respect identity and organisational boundaries

Neither account holder is automatically the actor. The starting identity may be a victim, and the target holder may have had no involvement.

Pivots can cross supplier, customer, tenant or directory boundaries. Preserve stable provider and tenant identifiers rather than joining accounts by similar display name. State each technical account transition before considering who controlled the resulting sessions.

Key takeaway

Trace account pivoting through the administrative or recovery event that links two identities, then prove later use without implicating either account holder by assumption.

Reference: CIM-137Cyber Incidents & Offender Methods