An organization is developing a threat hunting hypothesis based on MITRE ATT&CK technique T1078 (Valid Accounts). Which hunting query methodology best aligns with detecting this technique?
Service accounts logging in interactively represents an anomaly indicative of valid account misuse.
Why this answer
Detecting valid accounts abuse involves hunting for anomalous login locations, impossible travel, or unusual privilege escalations.