Cross-source coverage
T1556 / ATT&CK
Modify Authentication Process
154 rules across 10 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.
Adversaries may maliciously modify a part of this process to either reveal credentials or bypass authentication mechanisms. Compromised credentials or access may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access and remote desktop.
- Tactics
- Defense Impairment · Persistence · Credential Access
- Platforms
- IaaS · Identity Provider · Linux · macOS · Network Devices · Office Suite · SaaS · Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlogmacos:osqueryazure:policym365:unifiedAWS:CloudTrail
How MITRE says to detect it DET0104
Detect Modification of Authentication Processes Across Platforms
Windows Analytic 0287
Detects modification of LSASS and authentication DLLs, suspicious registry changes to password filter packages, and abnormal process access to lsass.exe. Correlates registry modifications, DLL loads, and process handle access events.
WinEventLog:SecurityEventCode=4657WinEventLog:SysmonEventCode=10WinEventLog:SysmonEventCode=7
Linux Analytic 0288
Detects modification of PAM configuration files, unauthorized new PAM modules, and suspicious process execution accessing PAM-related binaries. Correlates file modification events in /etc/pam.d/ with process execution of unauthorized binaries.
auditd:SYSCALLopen, writeauditd:SYSCALLexecve
macOS Analytic 0289
Detects unauthorized additions or changes to /Library/Security/SecurityAgentPlugins and suspicious process activity attempting to hook authentication APIs. Correlates file modifications with abnormal plugin loads in authentication flows.
macos:unifiedlogSecurityAgentPlugins modificationmacos:osqueryprocess_open
Identity Provider Analytic 0290
Detects suspicious configuration changes in IdP authentication flows such as enabling reversible password encryption, MFA bypass, or policy weakening. Correlates policy modification events with unusual administrative activity.
azure:policyUpdatePolicym365:unifiedSet-ADUser OR Set-ADAccountControl
IaaS Analytic 0291
Detects unauthorized changes to IAM authentication configurations such as disabling MFA, creating backdoor access keys, or altering trust policies. Correlates identity policy updates with unusual login behavior.
AWS:CloudTrailUpdateLoginProfileAWS:CloudTrailUpdateAccountPasswordPolicy
Sub-techniques with coverage
Counted in the 154 above — a rule tagged a sub-technique covers this technique too.
elastic/detection-rules
46 rules| Detection | Severity | Format |
|---|---|---|
| AWS IAM Deactivation of MFA Device | High | Elastic TOML |
| AWS IAM Virtual MFA Device Registration Attempt with Session Token | High | Elastic TOML |
| Deprecated - MFA Disabled for Google Workspace Organization | High | Elastic TOML |
| Entra ID Conditional Access Policy (CAP) Modified | High | Elastic TOML |
| Entra ID Domain Federation Configuration Change | High | Elastic TOML |
| Entra ID OAuth Application Redirect URI Modified | High | Elastic TOML |
| Entra ID Protection - Risk Detection - Sign-in Risk | High | Elastic TOML |
| Entra ID Protection - Risk Detection - User Risk | High | Elastic TOML |
| Google Workspace 2SV Policy Disabled By User | High | Elastic TOML |
| Google Workspace MFA Enforcement Disabled For Organization | High | Elastic TOML |
+ 36 more from elastic/detection-rules → showing the 10 highest-severity
splunk/security_content
31 rules| Detection | Severity | Format |
|---|---|---|
| ASL AWS Multi-Factor Authentication Disabled | Undefined | SPL |
| ASL AWS New MFA Method Registered For User | Undefined | SPL |
| AWS Multi-Factor Authentication Disabled | Undefined | SPL |
| AWS New MFA Method Registered For User | Undefined | SPL |
| Azure AD Multi-Factor Authentication Disabled | Undefined | SPL |
| Azure AD New MFA Method Registered For User | Undefined | SPL |
| Cisco ASA - AAA Policy Tampering | Undefined | SPL |
| Cisco Duo Admin Login Unusual Browser | Undefined | SPL |
| Cisco Duo Admin Login Unusual Country | Undefined | SPL |
| Cisco Duo Admin Login Unusual Os | Undefined | SPL |
+ 21 more from splunk/security_content → showing the 10 highest-severity
panther-labs/panther-analysis
29 rules| Detection | Severity | Format |
|---|---|---|
| Azure Authentication Methods Policy OIDC Discovery URL Changed | High | Panther Python |
| Azure MFA Disabled | High | Panther Python |
| GCP Org or Folder Policy Was Changed Manually | High | Panther Python |
| MFA Disabled | High | Panther Python |
| MongoDB access allowed from anywhere | High | Panther Python |
| MongoDB org membership restriction disabled | High | Panther Python |
| Okta AiTM Phishing Attempt Blocked by FastPass | High | Panther Python |
| Okta Authentication Bypass via Skeleton Key Injection - Behavioral | High | Panther Python |
| Okta Cleartext Passwords Extracted via SCIM Application | High | Panther Python |
| Okta Identity Provider Created or Modified | High | Panther Python |
+ 19 more from panther-labs/panther-analysis → showing the 10 highest-severity
SigmaHQ/sigma
19 rules| Detection | Severity | Format |
|---|---|---|
| AWS Identity Center Identity Provider Change | High | Sigma |
| Directory Service Restore Mode(DSRM) Registry Value Tampering | High | Sigma |
| Disabling Multi Factor Authentication | High | Sigma |
| Github High Risk Configuration Disabled | High | Sigma |
| Possible Shadow Credentials Added | High | Sigma |
| Powershell Install a DLL in System Directory | High | Sigma |
| CA Policy Removed by Non Approved Actor | Medium | Sigma |
| CA Policy Updated by Non Approved Actor | Medium | Sigma |
| Certificate-Based Authentication Enabled | Medium | Sigma |
| Change to Authentication Method | Medium | Sigma |
+ 9 more from SigmaHQ/sigma → showing the 10 highest-severity
Azure/Azure-Sentinel
10 rules| Detection | Severity | Format |
|---|---|---|
| Excessive number of HTTP authentication failures from a source (ASIM Web Session schema) | Low | KQL |
| External User Access Enabled | Low | KQL |
| Account MFA Modifications | Undefined | KQL |
| Approved Access Packages Details | Undefined | KQL |
| Conditional Access policy disabled or deleted | Undefined | KQL |
| Conditional Access policy exclusion added | Undefined | KQL |
| High Risk Sign In Around Authentication Method Added or Device Registration | Undefined | KQL |
| MFA method registered from an IP address not seen in user sign-in history | Undefined | KQL |
| Sign-in from unseen IP within 60 minutes of MFA disabled for account | Undefined | KQL |
| Temporary Access Pass created for user account | Undefined | KQL |
socfortress/Wazuh-Rules
7 rules| Detection | Severity | Format |
|---|---|---|
| Possible compilation of custom PAM module (T1556.003) | High | Wazuh XML |
| Possible PAM backdoor rule inserted (T1556.003) | High | Wazuh XML |
| Suspicious PAM module path used from temp directory (T1556.003) | High | Wazuh XML |
| T1556.002 - Password Filter DLL Registration detected: Modification of LSA Authentication Packages registry key. | High | Wazuh XML |
| T1556.002 - Password Filter DLL Registration detected: Modification of LSA Notification Packages registry key. | High | Wazuh XML |
| Use of pam_succeed_if.so may indicate PAM rule bypass attempt (T1556.003) | High | Wazuh XML |
| Write to PAM configuration file (T1556.003) | Medium | Wazuh XML |
chronicle/detection-rules
5 rules| Detection | Severity | Format |
|---|---|---|
| google_workspace_mfa_disabled | High | YARA-L |
| onelogin_user_authentication_factor_removed | High | YARA-L |
| aws_multi_factor_authentication_disabled | Medium | YARA-L |
| aws_new_mfa_method_registered_for_user | Medium | YARA-L |
| okta_user_password_and_mfa_factor_reset_or_deactivated | Medium | YARA-L |
Bert-JanP/Hunting-Queries-Detection-Rules
4 rules| Detection | Severity | Format |
|---|---|---|
| Anomalous Amount of URLClickEvents | Undefined | KQL |
| Change Conditional Access Policy | Undefined | KQL |
| Deletion Conditional Access Policy | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
elastic/protections-artifacts
2 rules| Detection | Severity | Format |
|---|---|---|
| Suspicious Windows Authentication Registry Modification | Undefined | Elastic TOML |
| Unusual SSH Parent/Child Execution | Undefined | Elastic TOML |
falcosecurity/rules
1 rule| Detection | Severity | Format |
|---|---|---|
| Backdoored library loaded into SSHD (CVE-2024-3094) | Medium | Falco YAML |