Modify Authentication Process: Multi-Factor Authentication T1556.006
Tactics: Defense Impairment, Persistence, Credential Access
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Authoring guide
Patterns shared across the 33 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (51 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (106 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (7 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 3 rules
- Azure AD Only Single Factor Authentication Required
- Disabling Multi Factor Authentication
- Okta MFA Reset or Deactivated
Elastic 11 rules
- Attempt to Deactivate an Okta Policy
- Attempt to Delete an Okta Policy
- Attempt to Reset MFA Factors for an Okta User Account
- AWS IAM Deactivation of MFA Device
- AWS IAM Virtual MFA Device Registration Attempt with Session Token
- AWS STS AssumeRole with New MFA Device
- Entra ID MFA Disabled for User
- Entra ID User Sign-in with Unusual Authentication Type
- Google Workspace MFA Enforcement Disabled
- MFA Deactivation with no Re-Activation for Okta User Account
- Stolen Credentials Used to Login to Okta Account After MFA Reset
Splunk 11 rules
- ASL AWS Multi-Factor Authentication Disabled
- ASL AWS New MFA Method Registered For User
- AWS Multi-Factor Authentication Disabled
- AWS New MFA Method Registered For User
- Azure AD Multi-Factor Authentication Disabled
- Azure AD New MFA Method Registered For User
- GCP Multi-Factor Authentication Disabled
- Okta Multi-Factor Authentication Disabled
- PingID Mismatch Auth Source and Verification Response
- PingID New MFA Method After Credential Reset
- PingID New MFA Method Registered For User
Kusto 2 rules
YARA-L 4 rules
- AWS MultiFactor Authentication Disabled
- AWS New MFA Method Registered For User
- Okta User Password and MFA Factor Reset or Deactivated
- OneLogin User Authentication Factor Removed