Insider Threat Matrix™Insider Threat Matrix™
  • ID: PR044.006
  • Created: 05th August 2026
  • Updated: 05th August 2026
  • Contributor: The ITM Team

Privileged and High-Value Account Discovery

A subject specifically identifies or enumerates privileged, administrative, executive, security, dormant, emergency, or other high-value organizational identities.

 

The subject may search for membership of administrative groups, privileged cloud roles, domain administrators, security personnel, executive accounts, service accounts with elevated access, emergency access identities, or accounts with authority over sensitive systems and business processes.

 

This behavior is distinct from broad account discovery because the subject selectively targets identities whose authority, access, organizational position, or reduced oversight could support a later infringement. The discovered identities may be targeted for credential collection, impersonation, privilege elevation, persistence, unauthorized approval, or anti-forensic account misuse.

 

Investigators should examine the names, roles, groups, and attributes queried; whether the subject searched for terminology associated with elevated access; and whether the activity was followed by credential access, authentication attempts, social engineering, or requests involving the identified accounts.