Modify Authentication Process T1556

Tactics: Defense Impairment, Persistence, Credential Access

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Events covered

21 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 170 rules share fields, values, and exclusions.

Fields filtered most (193 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType33eq 23, in 11exec, modification, ProcessRollup2, allow_strong_authentication, enforce_strong_authentication
data_stream.dataset28eq 27, in 1okta.system, aws.cloudtrail, azure.auditlogs, azure.identity_protection, azure.signinlogs
sourcetype26eq 26cisco:duo:administrator, cisco:duo:activity, aws:asl, aws:cloudtrail, azure:monitor:aad
action21eq 17, contains 2, in 2policy_create, policy_update, disblmfa, UpdateIPRestrictions, UpdateLoginSettings
host.os.type17eq 17
event.outcome12eq 12success
event.type11eq 11start, change, creation, end
EventID10eq 9, in 124, 4103, 4104, 4688, 4723
process_name9eq 5, in 5, is_not_null 1, starts_with 1sshd, ssh, ., azureadconnectauthenticationagentservice.exe, bash
OperationName8eq 5, contains 3, in 2Add member to group, Add named location, Delete conditional access policy, add service principal, admin deleted security info
Provider_Name7eq 7iam.amazonaws.com, admin, rds.amazonaws.com, rolesanywhere.amazonaws.com, sts.amazonaws.com
TargetFilename7starts_with 3, wildcard 3, contains 1, ends_with 1, eq 1, in 1, match 1*/.vscode/extensions/*mcp*, */appdata/roaming/cursor/*mcp*, /.claude/, /boot/efi/efi/*/grub.cfg, /boot/grub/grub.cfg
eventType7eq 5, contains 1, in 1application.lifecycle.update, user.authentication.auth_via_mfa, application.lifecycle.activate, application.lifecycle.create, system.idp.lifecycle
type7eq 7, starts_with 1TAILNET, 2sv_change, IdentityProvider, POSTURE, POSTURE_INTEGRATION
Image6is_not_null 2, starts_with 2, ends_with 1, wildcard 1./, ./*, /bin/, /boot/, /boot/*

Top indicator values (811 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
12369
sourcetypeeq
cisco:duo:administrator
1010
sourcetypeeq
cisco:duo:activity
44
data_stream.dataseteq
okta.system
948
data_stream.dataseteq
aws.cloudtrail
6169
data_stream.dataseteq
azure.auditlogs
426
actioneq
policy_create
88
actioneq
policy_update
89
event.typeeq
start
61078
event.typeeq
change
394
event.typeeq
creation
353
Actioneq
UPDATE
44
EventTypeeq
exec
4576
EventTypeeq
modification
272
typeeq
TAILNET
44
Provider_Nameeq
iam.amazonaws.com
332
action.nameeq
admin_login
33
log_sourceeq
auditevents
312
AppNamestarts_with
ConnectSyncProvisioning_
22
AttributeLDAPDisplayNameeq
msds-keycredentiallink
22
Categoryeq
usermanagement
211
EventTypein
ProcessRollup2
2117
EventTypein
allow_strong_authentication
22
EventTypein
enforce_strong_authentication
22
EventTypein
exec
2201
EventTypein
exec_event
2149
OldCredentialNamescross_field_compare
NewCredentialNames
2
TargetObjectwildcard
hklm\system\*controlset*\services\*\networkprovider\providerpath
22
aws::eventNameeq
createvirtualmfadevice
22
aws::eventNameeq
deactivatemfadevice
22

Exclusions (397 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Detailseq
?:\program files (x86)\citrix\ica client\x64\pnsson.dll
2
Imagein
./usr/bin/podman
2
Imagein
/bin/autossl_check
2
Imagein
/bin/chef-client
2
Imagein
/bin/dnf
2
Imagein
/bin/dnf-automatic
2
Imagein
/bin/dockerd
2
Imagein
/bin/dpkg
2
Imagein
/bin/dpkg-divert
2
Imagein
/bin/microdnf
2
Imagein
/bin/pacman
2
Imagein
/bin/pamac-daemon
2
Imagein
/bin/podman
2
Imagein
/bin/puppet
2
Imagein
/bin/rpm
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 20 rules

Elastic 47 rules

Splunk 35 rules

Kusto 32 rules

YARA-L 5 rules

Panther 31 rules