Vendor Sheet
Exabeam Account Manipulation
Account manipulation is a persistence technique used by attackers to maintain network access by creating or modifying user accounts and group memberships. Threat groups like APT3 have used this method to add accounts to local admin groups and retain elevated privileges. After initial compromise, attackers use these techniques to move laterally, remain covert, and access critical resources, often by increasing group privileges. Because these actions can resemble legitimate administration, they are difficult to detect. Exabeam addresses this by analyzing directory activity, account changes, and permission modifications while using user context such as role and department to distinguish normal administrative actions from suspicious behavior. This improves detection of potential compromise and
