Modify Authentication Process

T1556

Technique with 9 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Adversaries may maliciously modify a part of this process to either reveal credentials or bypass authentication mechanisms. Compromised credentials or access may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access and remote desktop.

Detection rules50

Rules on DetectionCode tagged with T1556 or one of its sub-techniques.

Sigma19

Splunk31

RuleTypeRiskData sourceTechnique
ASL AWS Multi-Factor Authentication DisabledTTPNULLASL AWS CloudTrailT1556.006
ASL AWS New MFA Method Registered For UserTTPNULLASL AWS CloudTrailT1556.006
AWS Multi-Factor Authentication DisabledTTPNULLAWS CloudTrail DeleteVirtualMFADevice, AWS CloudTrail DeactivateMFADeviceT1556.006
AWS New MFA Method Registered For UserTTPNULLAWS CloudTrail CreateVirtualMFADeviceT1556.006
Azure AD Multi-Factor Authentication DisabledTTPNULLAzure Active Directory Disable Strong AuthenticationT1556.006
Azure AD New MFA Method Registered For UserTTPNULLAzure Active Directory User registered security infoT1556.006
Cisco ASA - AAA Policy TamperingAnomalyNULLCisco ASA LogsT1556.004
Cisco Duo Admin Login Unusual BrowserTTPNULLCisco Duo ActivityT1556
Cisco Duo Admin Login Unusual CountryTTPNULLCisco Duo ActivityT1556
Cisco Duo Admin Login Unusual OsTTPNULLCisco Duo ActivityT1556
Cisco Duo Bulk Policy DeletionTTPNULLCisco Duo AdministratorT1556
Cisco Duo Bypass Code GenerationTTPNULLCisco Duo AdministratorT1556
Cisco Duo Policy Allow Devices Without Screen LockTTPNULLCisco Duo AdministratorT1556
Cisco Duo Policy Allow Network Bypass 2FATTPNULLCisco Duo AdministratorT1556
Cisco Duo Policy Allow Old FlashTTPNULLCisco Duo AdministratorT1556

Sub-techniques9

IDNameExamples
T1556.001Domain Controller Authentication2
T1556.002Password Filter DLL4
T1556.003Pluggable Authentication Modules2
T1556.004Network Device Authentication3
T1556.005Reversible Encryption0
T1556.006Multi-Factor Authentication4
T1556.007Hybrid Identity2
T1556.008Network Provider DLL0
T1556.009Conditional Access Policies2

Groups1

Software4

Campaigns1

Procedure examples6

Groups1

Used byProcedure example
GroupFIN13

FIN13 has replaced legitimate KeePass binaries with trojanized versions to collect passwords from numerous applications.

Software4

Used byProcedure example
MalwareDRYHOOK

DRYHOOK has intercepted and logged user credentials by modifying the Perl module in Ivanti Connect Secure VPN edge-devices located within `/home/perl/DSAuth.pm`.

MalwareEbury

Ebury can intercept private keys using a trojanized ssh-add function.

MalwareKessel

Kessel has trojanized the <sode>ssh_login</code> and user-auth_pubkey functions to steal plaintext credentials.

ToolSILENTTRINITY

SILENTTRINITY can create a backdoor in KeePass using a malicious config file and in TortoiseSVN using a registry hook.

Campaigns1

Used byProcedure example
CampaignArcaneDoor

ArcaneDoor included modification of the AAA process to bypass authentication mechanisms.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.