Skip to main content
T1199Initial Accesshard difficulty

Trusted Relationship

Trusted Relationship abuses an organization indirectly, through a third party that already holds access, such as a managed service provider, IT contractor, auditor, or vendor connection that receives less scrutiny than employee accounts. The attacker rides that legitimate trust inward. Detection depends on knowing the relationship: inventory third-party accounts and connections, then alert when they reach systems outside their stated scope, operate at unusual hours, or show a sudden change in access patterns.

Practice detecting Trusted Relationship on realistic SIEM, Firewall alerts in SOCSimulator Operations.

SIEMFirewall

What is Trusted Relationship?

Trusted Relationship is documented as technique T1199 in MITRE ATT&CK® v19.1 under the Initial Access tactic. Detection requires visibility into SIEM, Firewall telemetry.

Detection Strategies

The following detection strategies help SOC analysts identify Trusted Relationship activity. These methods apply across SIEM, Firewall environments and can be implemented as detection rules, correlation queries, or behavioral analytics in your security platform.

  1. 1

    Maintain an inventory of all third-party accounts and connections with their associated business justifications, and periodically audit these accounts to confirm they are still required and have not been over-provisioned with unnecessary permissions.

  2. 2

    Monitor authentication events from third-party accounts and alert on logins occurring outside scheduled maintenance windows, logins from IP addresses not associated with the partner organization, and access to systems beyond the partner scope of support.

  3. 3

    Implement just-in-time access for vendor and partner accounts so that credentials are only activated for the duration of authorized work sessions, reducing the window of opportunity if a partner account is compromised.

  4. 4

    Alert on lateral movement originating from systems or accounts associated with managed service providers or other trusted partners, as legitimate support activities rarely require moving between systems in patterns consistent with reconnaissance.

  5. 5

    Review network segmentation controls that apply to trusted third-party connections to ensure partners only have network-level access to the specific systems they support, limiting the blast radius if a partner account is used maliciously.

Example Alerts

These realistic alert examples show what Trusted Relationship looks like in your security tools. Use them to tune detection rules and train analysts to recognize true positives versus false positives in live environments.

HighSIEM

MSP Account Accessing Systems Outside Support Scope

Managed service provider account msp_operations_user accessed the finance application server and HR directory systems over the past 3 hours. This account is authorized only for IT infrastructure management across server and networking equipment. The access to business application systems falls outside the contracted support scope and the MSP has not submitted any change requests for these systems.

CriticalSIEM

Vendor VPN Connection at Unusual Time with Lateral Movement

Third-party auditing firm account audit_connector authenticated to the vendor VPN at 02:38 AM on a Saturday and subsequently accessed 14 internal servers including two domain controllers. The vendor normally connects during business hours on weekdays for scheduled audit activities. No audit work was scheduled this weekend, and the access pattern to domain controllers is inconsistent with legitimate auditing workflows.

HighFirewall

Contractor Account Used from Unexpected Geographic Location

Contractor account contractor_dev_team authenticated from an IP address geolocating to Eastern Europe. The contracting firm is based in Canada and has never previously authenticated from this region. The account immediately began accessing source code repositories and development infrastructure. This access pattern suggests the contractor account has been compromised and is being used by a threat actor.

Frequently Asked Questions

How do SOC analysts detect Trusted Relationship?
Detection centers on SIEM, Firewall telemetry for the initial access phase of the attack. Maintain an inventory of all third-party accounts and connections with their associated business justifications, and periodically audit these accounts to confirm they are still required and have not been over-provisioned with unnecessary permissions. Monitor authentication events from third-party accounts and alert on logins occurring outside scheduled maintenance windows, logins from IP addresses not associated with the partner organization, and access to systems beyond the partner scope of support.
What does a Trusted Relationship alert look like?
A representative SIEM detection is "MSP Account Accessing Systems Outside Support Scope" (high severity): Managed service provider account msp_operations_user accessed the finance application server and HR directory systems over the past 3 hours. This account is authorized only for IT infrastructure management across server and networking equipment. The access to business application systems falls outside the contracted support scope and the MSP has not submitted any change requests for these systems.
Which tools detect Trusted Relationship, and how can I practice?
Trusted Relationship (T1199) is best surfaced with SIEM, Firewall telemetry, which exposes the initial access signals described above. Practice detecting it on those exact consoles in SOCSimulator Operations, free.
Glossary

What is Phishing? SOC Glossary

Phishing is a social engineering attack delivered via email, SMS, voice calls, or other channels that deceives recipient…

Read more
Glossary

What is Attack Surface? SOC Glossary

An organization's attack surface is the total set of points where an adversary could attempt unauthorized access: networ…

Read more
Glossary

What is Social Engineering? SOC Glossary

Social engineering is the psychological manipulation of individuals into performing actions or revealing information tha…

Read more
Glossary

What is IOC? SOC Glossary

An Indicator of Compromise (IOC) is an observable artifact, such as a file hash, IP address, domain name, URL, registry …

Read more
Career Path

SOC Analyst (Tier 1) Career Guide: Salary & Skills

Tier 1 SOC Analysts are the front line. You monitor alert queues, triage incoming detections, classify them as true or f…

Read more
Career Path

SOC Analyst (Tier 2) Career Guide: Salary & Skills

Tier 2 SOC Analysts handle the investigations that Tier 1 escalates. You dig into multi-stage attacks, coordinate contai…

Read more
Tool

SIEM Training Console: SOCSimulator

The SIEM console in SOCSimulator replicates the workflow of enterprise platforms like Splunk Enterprise Security, Micros…

Read more
Tool

Firewall Training Console: SOCSimulator

The Firewall console in SOCSimulator replicates the log analysis experience of enterprise platforms like Palo Alto Netwo…

Read more
Comparison

SOCSimulator Vs. Letsdefend: Platform Comparison

SOCSimulator wins on operational realism. You get multi-tool shift simulation with SLA pressure, noise injection, and al…

Read more
Glossary

SOC Glossary: Security Operations Terminology

Complete glossary of Security Operations Center terminology for aspiring SOC analysts.

Read more
Feature

Shift Mode: Real-Time SOC Simulation

Practice alert triage under realistic time pressure with SLA timers and noise injection.

Read more
Feature

Operations: Guided Training Operations

Structured CTF-style investigation operations covering real-world attack scenarios.

Read more