Skill Market

hunting for t1098 account manipulation

Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group

GitHub
githubcommunityai-agentsclaude-codecloud-securitycybersecuritydevsecopsethical-hacking
0.0
0 installs33.4K GitHub starsby mukul975

Skill Introduction

Overview
Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group

Core value

Turns reusable Debugging know-how into an installable skill, helping users complete github, community, ai-agents, claude-code work faster.

Target users

  • Developers, testers, and maintainers who handle Debugging tasks in Focus Code.
  • Teams that already trust workflows or content from mukul975.
  • Users who want standardized prompts, steps, or conventions instead of repeating setup work.

Best practices

  • Read the skill content first to confirm required inputs, expected outputs, and dependencies.
  • Try it on a small task before relying on it for critical work.
  • Add project-specific constraints such as coding style, target platform, test expectations, and delivery format.
  • For external sources, verify the source link, version, and recent maintenance activity.

Best use cases

  • Tasks related to github, community, ai-agents, claude-code that need a reusable execution flow.
  • Converting a community repo, team convention, or personal workflow into day-to-day assistance.
  • Starting from a proven skill instead of writing prompts or procedures from scratch.

Limits and boundaries

  • Results depend on the quality of the original skill content and may need human correction.
  • It does not replace code review, tests, security review, or professional judgment.
  • External tools, APIs, account permissions, and local dependencies still need separate setup.

Differentiation

  • Structured around Debugging, making it easier to discover and reuse than loose prompt snippets.
  • Marked as GitHub, which helps users judge trust and maintenance expectations.
  • Keeps the original source link available for repository, documentation, or discussion follow-up.
  • Tagged with github, community, ai-agents, claude-code, so it can be filtered by concrete task intent.

Install and use

Install
Copy Install Command
focus install hunting-for-t1098-account-manipulation-e41bc8
View source

Detail Preview

SKILL.md

Primary filemarkdown3 KB

name: hunting-for-t1098-account-manipulation description: Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs. domain: cybersecurity subdomain: threat-hunting tags:

  • threat-hunting
  • mitre-attack
  • t1098
  • account-manipulation
  • active-directory
  • persistence version: '1.0' author: mahipal license: Apache-2.0 d3fend_techniques:
  • Token Binding
  • Restore Access
  • Application Protocol Command Analysis
  • Password Authentication
  • Biometric Authentication nist_csf:
  • DE.CM-01
  • DE.AE-02
  • DE.AE-07
  • ID.RA-05

Hunting for T1098 Account Manipulation

Overview

MITRE ATT&CK T1098 (Account Manipulation) covers adversary actions to maintain or expand access to compromised accounts, including adding credentials, modifying group memberships, SID history injection, and creating shadow admin accounts. This skill covers detecting these techniques through Windows Security Event Log analysis (Event IDs 4738, 4728, 4732, 4756, 4670, 5136), correlating group membership changes with privilege escalation indicators, and identifying anomalous account modification patterns.

When to Use

  • When investigating security incidents that require hunting for t1098 account manipulation
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Windows Security Event Logs (EVTX format) or SIEM access
  • Python 3.9+ with python-evtx, lxml libraries
  • Understanding of Active Directory group structure and SID architecture
  • Familiarity with MITRE ATT&CK T1098 sub-techniques

Steps

Step 1: Parse Account Modification Events

Extract Event IDs 4738 (user account changed), 4728/4732/4756 (member added to security groups), and 5136 (directory service object modified).

Step 2: Detect Privileged Group Changes

Flag additions to Domain Admins, Enterprise Admins, Schema Admins, Administrators, and Backup Operators groups.

Step 3: Identify Shadow Admin Indicators

Detect accounts receiving AdminSDHolder protection, direct privilege assignment, or SID history injection.

Step 4: Correlate with Attack Timeline

Cross-reference account changes with authentication events to identify initial compromise and persistence establishment.

Expected Output

JSON report with detected account manipulation events, privileged group changes, shadow admin indicators, and timeline correlation.

Reviews

Overall rating

0.0
0.0

0 comments

No reviews yet