Modify Authentication Process T1556
Tactics: Defense Impairment, Persistence, Credential Access
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.
Events covered
21 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 170 rules share fields, values, and exclusions.
Fields filtered most (193 distinct)
These fields appear most often in rule filters.
Top indicator values (811 distinct)
These values appear most often in rule predicates.
Exclusions (397 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 20 rules
- AWS Identity Center Identity Provider Change
- Azure AD Only Single Factor Authentication Required
- CA Policy Removed by Non Approved Actor
- CA Policy Updated by Non Approved Actor
- Certificate-Based Authentication Enabled
- Change to Authentication Method
- Cisco Dot1x Disabled
- Directory Service Restore Mode(DSRM) Registry Value Tampering
- Disabled MFA to Bypass Authentication Mechanisms
- Disabling Multi Factor Authentication
- Dropping Of Password Filter DLL
- Github High Risk Configuration Disabled
- macOS Configuration Profile Installation
- New Root Certificate Authority Added
- Okta MFA Reset or Deactivated
- Possible Shadow Credentials Added
- Potential Suspicious Activity Using SeCEdit
- Powershell Install a DLL in System Directory
- User Added To Group With CA Policy Modification Access
- User Removed From Group With CA Policy Modification Access
Elastic 47 rules
- Attempt to Deactivate an Okta Policy
- Attempt to Deactivate an Okta Policy Rule
- Attempt to Delete an Okta Policy
- Attempt to Modify an Okta Policy
- Attempt to Reset MFA Factors for an Okta User Account
- Authentication via Unusual PAM Grantor
- Authorization Plugin Modification
- AWS IAM Account Password Policy Deleted
- AWS IAM Deactivation of MFA Device
- AWS IAM Roles Anywhere Trust Anchor Created with External CA
- AWS IAM Virtual MFA Device Registration Attempt with Session Token
- AWS RDS DB Instance Made Public
- AWS STS AssumeRole with New MFA Device
- Deprecated - MFA Disabled for Google Workspace Organization
- Entra ID Conditional Access MFA Bypass with Unusual User, Client and Source ASN
- Entra ID Conditional Access Policy (CAP) Modified
- Entra ID Domain Federation Configuration Change
- Entra ID External Authentication Methods (EAM) Modified
- Entra ID MFA Disabled for User
- Entra ID OAuth Application Redirect URI Modified
- Entra ID Protection - Risk Detection - Sign-in Risk
- Entra ID Protection - Risk Detection - User Risk
- Entra ID User Sign-in with Unusual Authentication Type
- Google Workspace 2SV Policy Disabled By User
- Google Workspace MFA Enforcement Disabled For Organization
- MFA Deactivation with no Re-Activation for Okta User Account
- Mimikatz Memssp Log File Detected
- Modification or Removal of an Okta Application Sign-On Policy
- Network Logon Provider Registry Modification
- New Okta Identity Provider (IdP) Added by Admin
- Pluggable Authentication Module (PAM) Creation in Unusual Directory
- Pluggable Authentication Module (PAM) Source Download
- Pluggable Authentication Module (PAM) Version Discovery
- Pluggable Authentication Module or Configuration Creation
- Polkit Policy Creation
- Potential Backdoor Execution Through PAM_EXEC
- Potential Execution via SSH Backdoor
- Potential OpenSSH Backdoor Logging Activity
- Potential Persistence via File Modification
- Potential Shadow Credentials added to AD Object
- Potential SSH Password Grabbing via strace
- Renaming of OpenSSH Binaries
- Stolen Credentials Used to Login to Okta Account After MFA Reset
- Suspicious Windows Authentication Registry Modification
- Untrusted DLL Loaded by Azure AD Connect Authentication Agent
- Unusual Process Modifying GenAI Configuration File
- Unusual SSH Parent/Child Execution
Splunk 35 rules
- ASL AWS Multi-Factor Authentication Disabled
- ASL AWS New MFA Method Registered For User
- AWS Multi-Factor Authentication Disabled
- AWS New MFA Method Registered For User
- Azure AD Multi-Factor Authentication Disabled
- Azure AD New MFA Method Registered For User
- Cisco ASA - AAA Policy Tampering
- Cisco Duo Admin Login Unusual Browser
- Cisco Duo Admin Login Unusual Country
- Cisco Duo Admin Login Unusual Os
- Cisco Duo Bulk Policy Deletion
- Cisco Duo Bypass Code Generation
- Cisco Duo Policy Allow Devices Without Screen Lock
- Cisco Duo Policy Allow Network Bypass 2FA
- Cisco Duo Policy Allow Old Flash
- Cisco Duo Policy Allow Old Java
- Cisco Duo Policy Allow Tampered Devices
- Cisco Duo Policy Bypass 2FA
- Cisco Duo Policy Deny Access
- Cisco Duo Policy Skip 2FA for Other Countries
- Cisco Duo Set User Status to Bypass 2FA
- Cisco Network Interface Modifications
- Disabling Windows Local Security Authority Defences via Registry
- GCP Multi-Factor Authentication Disabled
- O365 Disable MFA
- O365 Excessive SSO logon errors
- Okta Multi-Factor Authentication Disabled
- Okta Phishing Detection with FastPass Origin Check
- PingID Mismatch Auth Source and Verification Response
- PingID New MFA Method After Credential Reset
- PingID New MFA Method Registered For User
- Potential LSA password filter (PowerShell)
- Potential LSA password filter (Windows Event Log)
- Suspicious Certificate Authentication (Windows Event Log)
- Suspicious Certificate Modification (Windows Event Log)
Kusto 32 rules
- 1Password - Changes to SSO configuration
- 1Password - Disable MFA factor or type for all user accounts
- 1Password - User account MFA settings changed
- AWS Security Hub - Detect root user lacking MFA
- Azure secure score block legacy authentication
- Cross-Cloud Unauthorized Credential Access Detection From AWS RDS Login
- Detect changes to Connect Sync Application
- Detect credential add to Connect Sync Application
- Detect suspicious conditional access policy modifications
- Excessive number of HTTP authentication failures from a source (ASIM Web Session schema)
- External User Access Enabled
- F&O - Bank account change following network alias reassignment
- F&O - Non-interactive account mapped to self or sensitive privileged user
- GitLab - Repository visibility to Public
- Keeper Security - Password Changed
- Keeper Security - User MFA Changed
- Multi-Factor Authentication Disabled for a User
- New Device/Location sign-in along with critical operation
- NordPass - User fails authentication
- Red Sift - MFA disabled on account
- Rouge RDP: Suspicious File Creation
- SAP BTP - Cloud Identity Service application configuration monitor
- SAP BTP - Trust and authorization Identity Provider monitor
- Suspicious Sign In Followed by MFA Modification
- Tailscale Premium: Posture integration disabled or removed
- Tailscale: Device started advertising subnet routes
- Tailscale: DNS nameservers modified
- Tailscale: MagicDNS disabled
- Tailscale: Policy file (ACL) modified
- Tailscale: Split-DNS configuration modified
- Tailscale: Tailnet lock validation failed
- VMware ESXi - Root password changed
YARA-L 5 rules
- AWS MultiFactor Authentication Disabled
- AWS New MFA Method Registered For User
- Google Workspace MFA Disabled
- Okta User Password and MFA Factor Reset or Deactivated
- OneLogin User Authentication Factor Removed
Panther 31 rules
- AppOmni Alert Passthrough
- Azure Authentication Methods Policy OIDC Discovery URL Changed
- Azure Domain Federation Settings Modified
- Azure MFA Disabled
- Crowdstrike IP Allowlist Changed
- Crowdstrike Single IP Allowlisted
- Databricks MFA Key Change
- Databricks SSO Configuration Changed
- GCP Org or Folder Policy Was Changed Manually
- GSuite User Two Step Verification Change
- MFA Disabled
- Microsoft365 MFA Disabled
- MongoDB access allowed from anywhere
- MongoDB Identity Provider Activity
- MongoDB org membership restriction disabled
- Okta AiTM Phishing Attempt Blocked by FastPass
- Okta Authentication Bypass via Skeleton Key Injection - Behavioral
- Okta Cleartext Passwords Extracted via SCIM Application
- Okta Identity Provider Created or Modified
- Okta MFA Globally Disabled
- Okta Org2Org application created of modified
- Okta Sign-In from VPN Anonymizer
- OneLogin Authentication Factor Removed
- Slack IDP Configuration Changed
- Slack MFA Settings Changed
- Slack SSO Settings Changed
- Snowflake Login Without MFA
- Snowflake Login Without MFA
- Wiz Update IP Restrictions
- Wiz Update Login Settings
- ZIA Insecure Password Settings