Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/M1026
MITRE ATT&CK Mitigation

M1026: Privileged Account Management

ShareXLinkedInRedditHN

Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures: Account Permissions and Roles: - Implement RBAC and least privilege principles to allocate permissions securely. - Use tools like Active Directory Group Policies to enforce access restrictions. Credential Security: - Deploy password vaulting tools like CyberArk, HashiCorp Vault, or KeePass for secure storage and rotation of credentials. - Enforce password policies for complexity, uniqueness, and expiration using tools like Microsoft Group Policy Objects (GPO). Multi-Factor Authentication (MFA): - Enforce MFA for all privileged accounts using Duo Security, Okta, or Microsoft Azure AD MFA. Privileged Access Management (PAM): - Use PAM solutions like CyberArk, BeyondTrust, or Thycotic to manage, monitor, and audit privileged access. Auditing and Monitoring: - Integrate activity monitoring into your SIEM (e.g., Splunk or QRadar) to detect and alert on anomalous privileged account usage. Just-In-Time Access: - Deploy JIT solutions like Azure Privileged Identity Management (PIM) or configure ephemeral roles in AWS and GCP to grant time-limited elevated permissions. *Tools for Implementation* Privileged Access Management (PAM): - CyberArk, BeyondTrust, Thycotic, HashiCorp Vault. Credential Management: - Microsoft LAPS (Local Admin Password Solution), Password Safe, HashiCorp Vault, KeePass. Multi-Factor Authentication: - Duo Security, Okta, Microsoft Azure MFA, Google Authenticator. Linux Privilege Management: - sudo configuration, SELinux, AppArmor. Just-In-Time Access: - Azure Privileged Identity Management (PIM), AWS IAM Roles with session constraints, GCP Identity-Aware Proxy.

▪Techniques addressed (112)

T1053.005Scheduled TaskT1550.003Pass the TicketT1555.006Cloud Secrets Management StoresT1505.004IIS ComponentsT1556.005Reversible EncryptionT1555Credentials from Password StoresT1569.002Service ExecutionT1505.002Transport AgentT1047Windows Management InstrumentationT1552.002Credentials in RegistryT1098.003Additional Cloud RolesT1222.001Windows PermissionsT1556.003Pluggable Authentication ModulesT1021.006Windows Remote ManagementT1569System ServicesT1599Network Boundary BridgingT1003.008/etc/passwd and /etc/shadowT1072Software Deployment ToolsT1543Create or Modify System ProcessT1553.006Code Signing Policy ModificationT1484Domain or Tenant Policy ModificationT1547.006Kernel Modules and ExtensionsT1134.003Make and Impersonate TokenT1542.001System FirmwareT1078.002Domain AccountsT1190Exploit Public-Facing ApplicationT1078.004Cloud AccountsT1078.003Local AccountsT1688Safe Mode BootT1558.002Silver TicketT1612Build Image on HostT1484.002Trust ModificationT1098.002Additional Email Delegate PermissionsT1059.013Container CLI/APIT1003.003NTDST1222.002Linux and Mac PermissionsT1542.005TFTP BootT1134.002Create Process with TokenT1606Forge Web CredentialsT1559.001Component Object ModelT1611Escape to HostT1136.003Cloud AccountT1218System Binary Proxy ExecutionT1550Use Alternate Authentication MaterialT1053.007Container Orchestration JobT1553Subvert Trust ControlsT1003.002Security Account ManagerT1055Process InjectionT1548Abuse Elevation Control MechanismT1556.001Domain Controller AuthenticationT1552.007Container APIT1078Valid AccountsT1098.001Additional Cloud CredentialsT1525Implant Internal ImageT1053Scheduled Task/JobT1548.002Bypass User Account ControlT1021.002SMB/Windows Admin SharesT1548.006TCC ManipulationT1542.003BootkitT1222File and Directory Permissions ModificationT1609Container Administration CommandT1210Exploitation of Remote ServicesT1098Account ManipulationT1003OS Credential DumpingT1546Event Triggered ExecutionT1601.001Patch System ImageT1558.001Golden TicketT1556.007Hybrid IdentityT1546.003Windows Management Instrumentation Event SubscriptionT1003.001LSASS MemoryT1059Command and Scripting InterpreterT1056.003Web Portal CaptureT1550.002Pass the HashT1601.002Downgrade System ImageT1542Pre-OS BootT1136Create AccountT1495Firmware CorruptionT1606.002SAML TokensT1563.002RDP HijackingT1134Access Token ManipulationT1543.002Systemd ServiceT1136.001Local AccountT1003.005Cached Domain CredentialsT1556.004Network Device AuthenticationT1003.004LSA SecretsT1059.009Cloud APIT1559Inter-Process CommunicationT1505.001SQL Stored ProceduresT1055.008Ptrace System CallsT1599.001Network Address Translation TraversalT1003.007Proc FilesystemT1134.001Token Impersonation/TheftT1003.006DCSyncT1556Modify Authentication ProcessT1021.007Cloud ServicesT1601Modify System ImageT1053.002AtT1552Unsecured CredentialsT1563Remote Service Session HijackingT1563.001SSH HijackingT1059.001PowerShellT1021.001Remote Desktop ProtocolT1053.006Systemd TimersT1136.002Domain AccountT1021.003Distributed Component Object ModelT1059.008Network Device CLIT1218.007MsiexecT1505Server Software ComponentT1548.003Sudo and Sudo CachingT1651Cloud Administration CommandT1558.003KerberoastingT1558Steal or Forge Kerberos Tickets

▪Reference

M1026on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.