Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/M1026
MITRE ATT&CK Mitigation

M1026: Privileged Account Management

ShareXLinkedInRedditHN

Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures: Account Permissions and Roles: - Implement RBAC and least privilege principles to allocate permissions securely. - Use tools like Active Directory Group Policies to enforce access restrictions. Credential Security: - Deploy password vaulting tools like CyberArk, HashiCorp Vault, or KeePass for secure storage and rotation of credentials. - Enforce password policies for complexity, uniqueness, and expiration using tools like Microsoft Group Policy Objects (GPO). Multi-Factor Authentication (MFA): - Enforce MFA for all privileged accounts using Duo Security, Okta, or Microsoft Azure AD MFA. Privileged Access Management (PAM): - Use PAM solutions like CyberArk, BeyondTrust, or Thycotic to manage, monitor, and audit privileged access. Auditing and Monitoring: - Integrate activity monitoring into your SIEM (e.g., Splunk or QRadar) to detect and alert on anomalous privileged account usage. Just-In-Time Access: - Deploy JIT solutions like Azure Privileged Identity Management (PIM) or configure ephemeral roles in AWS and GCP to grant time-limited elevated permissions. *Tools for Implementation* Privileged Access Management (PAM): - CyberArk, BeyondTrust, Thycotic, HashiCorp Vault. Credential Management: - Microsoft LAPS (Local Admin Password Solution), Password Safe, HashiCorp Vault, KeePass. Multi-Factor Authentication: - Duo Security, Okta, Microsoft Azure MFA, Google Authenticator. Linux Privilege Management: - sudo configuration, SELinux, AppArmor. Just-In-Time Access: - Azure Privileged Identity Management (PIM), AWS IAM Roles with session constraints, GCP Identity-Aware Proxy.

▪Techniques addressed (112)

T1053.005Scheduled TaskT1550.003Pass the TicketT1555.006Cloud Secrets Management Stores

▪Reference

M1026on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

T1505.004IIS Components
T1556.005Reversible Encryption
T1555Credentials from Password Stores
T1569.002Service Execution
T1505.002Transport Agent
T1047Windows Management Instrumentation
T1552.002Credentials in Registry
T1098.003Additional Cloud Roles
T1222.001Windows Permissions
T1556.003Pluggable Authentication Modules
T1021.006Windows Remote Management
T1569System Services
T1599Network Boundary Bridging
T1003.008/etc/passwd and /etc/shadow
T1072Software Deployment Tools
T1543Create or Modify System Process
T1553.006Code Signing Policy Modification
T1484Domain or Tenant Policy Modification
T1547.006Kernel Modules and Extensions
T1134.003Make and Impersonate Token
T1542.001System Firmware
T1078.002Domain Accounts
T1190Exploit Public-Facing Application
T1078.004Cloud Accounts
T1078.003Local Accounts
T1688Safe Mode Boot
T1558.002Silver Ticket
T1612Build Image on Host
T1484.002Trust Modification
T1098.002Additional Email Delegate Permissions
T1059.013Container CLI/API
T1003.003NTDS
T1222.002Linux and Mac Permissions
T1542.005TFTP Boot
T1134.002Create Process with Token
T1606Forge Web Credentials
T1559.001Component Object Model
T1611Escape to Host
T1136.003Cloud Account
T1218System Binary Proxy Execution
T1550Use Alternate Authentication Material
T1053.007Container Orchestration Job
T1553Subvert Trust Controls
T1003.002Security Account Manager
T1055Process Injection
T1548Abuse Elevation Control Mechanism
T1556.001Domain Controller Authentication
T1552.007Container API
T1078Valid Accounts
T1098.001Additional Cloud Credentials
T1525Implant Internal Image
T1053Scheduled Task/Job
T1548.002Bypass User Account Control
T1021.002SMB/Windows Admin Shares
T1548.006TCC Manipulation
T1542.003Bootkit
T1222File and Directory Permissions Modification
T1609Container Administration Command
T1098Account Manipulation
T1601.001Patch System Image
T1558.001Golden Ticket
T1556.007Hybrid Identity
T1546.003Windows Management Instrumentation Event Subscription
T1003.001LSASS Memory
T1059Command and Scripting Interpreter
T1056.003Web Portal Capture
T1550.002Pass the Hash
T1601.002Downgrade System Image
T1542Pre-OS Boot
T1136Create Account
T1495Firmware Corruption
T1606.002SAML Tokens
T1563.002RDP Hijacking
T1134Access Token Manipulation
T1543.002Systemd Service
T1136.001Local Account
T1003.005Cached Domain Credentials
T1556.004Network Device Authentication
T1003.004LSA Secrets
T1059.009Cloud API
T1559Inter-Process Communication
T1505.001SQL Stored Procedures
T1055.008Ptrace System Calls
T1599.001Network Address Translation Traversal
T1003.007Proc Filesystem
T1134.001Token Impersonation/Theft
T1556Modify Authentication Process
T1021.007Cloud Services
T1601Modify System Image
T1053.002At
T1552Unsecured Credentials
T1563Remote Service Session Hijacking
T1563.001SSH Hijacking
T1059.001PowerShell
T1021.001Remote Desktop Protocol
T1053.006Systemd Timers
T1136.002Domain Account
T1021.003Distributed Component Object Model
T1059.008Network Device CLI
T1218.007Msiexec
T1505Server Software Component
T1548.003Sudo and Sudo Caching
T1651Cloud Administration Command
T1558.003Kerberoasting
T1210Exploitation of Remote Services
T1546Event Triggered Execution
T1003OS Credential Dumping
T1003.006DCSync
T1558Steal or Forge Kerberos Tickets