Cross-source coverage

T1556 / ATT&CK

Modify Authentication Process

154 rules across 10 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Adversaries may maliciously modify a part of this process to either reveal credentials or bypass authentication mechanisms. Compromised credentials or access may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access and remote desktop.

Platforms
IaaS · Identity Provider · Linux · macOS · Network Devices · Office Suite · SaaS · Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlogmacos:osqueryazure:policym365:unifiedAWS:CloudTrail

How MITRE says to detect it DET0104

Detect Modification of Authentication Processes Across Platforms

Windows Analytic 0287

Detects modification of LSASS and authentication DLLs, suspicious registry changes to password filter packages, and abnormal process access to lsass.exe. Correlates registry modifications, DLL loads, and process handle access events.

  • WinEventLog:Security EventCode=4657
  • WinEventLog:Sysmon EventCode=10
  • WinEventLog:Sysmon EventCode=7

Linux Analytic 0288

Detects modification of PAM configuration files, unauthorized new PAM modules, and suspicious process execution accessing PAM-related binaries. Correlates file modification events in /etc/pam.d/ with process execution of unauthorized binaries.

  • auditd:SYSCALL open, write
  • auditd:SYSCALL execve

macOS Analytic 0289

Detects unauthorized additions or changes to /Library/Security/SecurityAgentPlugins and suspicious process activity attempting to hook authentication APIs. Correlates file modifications with abnormal plugin loads in authentication flows.

  • macos:unifiedlog SecurityAgentPlugins modification
  • macos:osquery process_open

Identity Provider Analytic 0290

Detects suspicious configuration changes in IdP authentication flows such as enabling reversible password encryption, MFA bypass, or policy weakening. Correlates policy modification events with unusual administrative activity.

  • azure:policy UpdatePolicy
  • m365:unified Set-ADUser OR Set-ADAccountControl

IaaS Analytic 0291

Detects unauthorized changes to IAM authentication configurations such as disabling MFA, creating backdoor access keys, or altering trust policies. Correlates identity policy updates with unusual login behavior.

  • AWS:CloudTrail UpdateLoginProfile
  • AWS:CloudTrail UpdateAccountPasswordPolicy

Sub-techniques with coverage

Counted in the 154 above — a rule tagged a sub-technique covers this technique too.


elastic/detection-rules

46 rules
Detection Severity Format
AWS IAM Deactivation of MFA Device High Elastic TOML
AWS IAM Virtual MFA Device Registration Attempt with Session Token High Elastic TOML
Deprecated - MFA Disabled for Google Workspace Organization High Elastic TOML
Entra ID Conditional Access Policy (CAP) Modified High Elastic TOML
Entra ID Domain Federation Configuration Change High Elastic TOML
Entra ID OAuth Application Redirect URI Modified High Elastic TOML
Entra ID Protection - Risk Detection - Sign-in Risk High Elastic TOML
Entra ID Protection - Risk Detection - User Risk High Elastic TOML
Google Workspace 2SV Policy Disabled By User High Elastic TOML
Google Workspace MFA Enforcement Disabled For Organization High Elastic TOML

+ 36 more from elastic/detection-rules → showing the 10 highest-severity

splunk/security_content

31 rules
Detection Severity Format
ASL AWS Multi-Factor Authentication Disabled Undefined SPL
ASL AWS New MFA Method Registered For User Undefined SPL
AWS Multi-Factor Authentication Disabled Undefined SPL
AWS New MFA Method Registered For User Undefined SPL
Azure AD Multi-Factor Authentication Disabled Undefined SPL
Azure AD New MFA Method Registered For User Undefined SPL
Cisco ASA - AAA Policy Tampering Undefined SPL
Cisco Duo Admin Login Unusual Browser Undefined SPL
Cisco Duo Admin Login Unusual Country Undefined SPL
Cisco Duo Admin Login Unusual Os Undefined SPL

+ 21 more from splunk/security_content → showing the 10 highest-severity

panther-labs/panther-analysis

29 rules
Detection Severity Format
Azure Authentication Methods Policy OIDC Discovery URL Changed High Panther Python
Azure MFA Disabled High Panther Python
GCP Org or Folder Policy Was Changed Manually High Panther Python
MFA Disabled High Panther Python
MongoDB access allowed from anywhere High Panther Python
MongoDB org membership restriction disabled High Panther Python
Okta AiTM Phishing Attempt Blocked by FastPass High Panther Python
Okta Authentication Bypass via Skeleton Key Injection - Behavioral High Panther Python
Okta Cleartext Passwords Extracted via SCIM Application High Panther Python
Okta Identity Provider Created or Modified High Panther Python

+ 19 more from panther-labs/panther-analysis → showing the 10 highest-severity

SigmaHQ/sigma

19 rules
Detection Severity Format
AWS Identity Center Identity Provider Change High Sigma
Directory Service Restore Mode(DSRM) Registry Value Tampering High Sigma
Disabling Multi Factor Authentication High Sigma
Github High Risk Configuration Disabled High Sigma
Possible Shadow Credentials Added High Sigma
Powershell Install a DLL in System Directory High Sigma
CA Policy Removed by Non Approved Actor Medium Sigma
CA Policy Updated by Non Approved Actor Medium Sigma
Certificate-Based Authentication Enabled Medium Sigma
Change to Authentication Method Medium Sigma

+ 9 more from SigmaHQ/sigma → showing the 10 highest-severity

Azure/Azure-Sentinel

10 rules
Detection Severity Format
Excessive number of HTTP authentication failures from a source (ASIM Web Session schema) Low KQL
External User Access Enabled Low KQL
Account MFA Modifications Undefined KQL
Approved Access Packages Details Undefined KQL
Conditional Access policy disabled or deleted Undefined KQL
Conditional Access policy exclusion added Undefined KQL
High Risk Sign In Around Authentication Method Added or Device Registration Undefined KQL
MFA method registered from an IP address not seen in user sign-in history Undefined KQL
Sign-in from unseen IP within 60 minutes of MFA disabled for account Undefined KQL
Temporary Access Pass created for user account Undefined KQL

socfortress/Wazuh-Rules

7 rules
Detection Severity Format
Possible compilation of custom PAM module (T1556.003) High Wazuh XML
Possible PAM backdoor rule inserted (T1556.003) High Wazuh XML
Suspicious PAM module path used from temp directory (T1556.003) High Wazuh XML
T1556.002 - Password Filter DLL Registration detected: Modification of LSA Authentication Packages registry key. High Wazuh XML
T1556.002 - Password Filter DLL Registration detected: Modification of LSA Notification Packages registry key. High Wazuh XML
Use of pam_succeed_if.so may indicate PAM rule bypass attempt (T1556.003) High Wazuh XML
Write to PAM configuration file (T1556.003) Medium Wazuh XML

chronicle/detection-rules

5 rules
Detection Severity Format
google_workspace_mfa_disabled High YARA-L
onelogin_user_authentication_factor_removed High YARA-L
aws_multi_factor_authentication_disabled Medium YARA-L
aws_new_mfa_method_registered_for_user Medium YARA-L
okta_user_password_and_mfa_factor_reset_or_deactivated Medium YARA-L

Bert-JanP/Hunting-Queries-Detection-Rules

4 rules
Detection Severity Format
Anomalous Amount of URLClickEvents Undefined KQL
Change Conditional Access Policy Undefined KQL
Deletion Conditional Access Policy Undefined KQL
MITRE ATT&CK Mapping Undefined KQL

elastic/protections-artifacts

2 rules
Detection Severity Format
Suspicious Windows Authentication Registry Modification Undefined Elastic TOML
Unusual SSH Parent/Child Execution Undefined Elastic TOML

falcosecurity/rules

1 rule
Detection Severity Format
Backdoored library loaded into SSHD (CVE-2024-3094) Medium Falco YAML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.