Meta tags:
Headings (most frequently used words):
modify, authentication, process, procedure, examples, mitigations, detection, strategy, references, sub, techniques,
Text of the page (most frequently used words):
and (33), the (27), #authentication (25), t1556 (20), access (18), retrieved (15), process (15), for (13), all (11), accounts (11), att (10), are (10), microsoft (10), may (10), network (9), such (9), that (9), credentials (9), policy (8), enterprise (8), with (8), registry (8), april (7), modification (7), ensure (7), system (7), can (7), techniques (6), 2022 (6), mfa (6), file (6), mechanisms (6), 2026 (5), ics (5), mobile (5), none (5), privileged (5), using (5), new (5), detects (5), correlates (5), identity (5), password (5), pam (5), dlls (5), user (5), account (5), restrict (5), hkey_local_machine (5), windows (5), provider (5), review (5), modify (5), mitre (4), use (4), resources (4), detection (4), tactics (4), february (4), 2016 (4), january (4), directory (4), modules (4), 2025 (4), secure (4), unauthorized (4), changes (4), policies (4), suspicious (4), configuration (4), bypass (4), security (4), binaries (4), dll (4), name (4), currentcontrolset (4), control (4), networkprovider (4), limit (4), hybrid (4), only (4), through (4), local (4), valid (4), used (4), version (4), systems (4), registered (3), reference (3), cti (3), data (3), components (3), mitigations (3), defenses (3), sub (3), lsa (3), october (3), privilege (3), administrative (3), reversible (3), encryption (3), 2023 (3), august (3), september (3), 2020 (3), azure (3), silenttrinity (3), fin13 (3), ebury (3), ivanti (3), connect (3), arcanedoor (3), found (3), devices (3), keys (3), events (3), lsass (3), filter (3), description (3), management (3), permissions (3), these (3), from (3), modifying (3), domain (3), adversary (3), have (3), service (3), multi (3), factor (3), within (3), services (3), has (3), trojanized (3), 2015 (2), corporation (2), filters (2), domains (2), campaigns (2), software (2), groups (2), analytics (2), strategies (2), assets (2), matrices (2), core (2), objects (2), july (2), additional (2), june (2), credential (2), passwords (2), march (2), threat (2), team (2), 365 (2), authenticate (2), backdoors (2), 2019 (2), léveillé (2), focused (2), linux (2), vpn (2), backdoor (2), updates (2), unusual (2), flows (2), activity (2), library (2), securityagentplugins (2), hook (2), apis (2), modifications (2), abnormal (2), loads (2), files (2), execution (2), etc (2), packages (2), processes (2), across (2), platforms (2), analytic (2), proper (2), order (2), enabled (2), protected (2), solution (2), example (2), global (2), cloud (2), ones (2), prevent (2), audit (2), also (2), default (2), created (2), disabled (2), controller (2), corresponding (2), part (2), periodically (2), networkprovidername (2), any (2), signed (2), keepass (2), kessel (2), perl (2), home (2), dryhook (2), macos (2), 009 (2), 008 (2), 007 (2), 006 (2), 005 (2), 004 (2), 003 (2), 002 (2), 001 (2), adversaries (2), remote (2), pluggable (2), ckcon (2), person (2), tickets (2), faq (2), trademarks, cookie, preferences, website, changelog, privacy, terms, contact, reset, 2013, configuring, protection, plett, poggemeyer, securing, material, 2017, implementing, least, models, attractive, theft, 2021, store, csp, windowslogon, intelligence, center, response, defender, research, magicweb, nobelium, post, compromise, trick, anyone, mike, burns, detecting, active, salvati, dumont, porcher, 2018, december, dark, side, forsshe, landscape, openssh, cybercriminal, actor, mexico, 2014, depth, analysis, sila, ozeren, hacioglu, unc5221, latest, exploit, weaponizing, cve, 22457, john, wolfram, josh, murchie, matt, lin, daniel, ainsworth, robert, wallace, dimiter, andonov, dhanesh, kizhakkinan, jacob, thompson, targeted, zero, day, exploitation, cisco, talos, 2024, espionage, campaign, targeting, perimeter, references, iam, configurations, disabling, creating, altering, trust, login, behavior, an0291, idp, enabling, weakening, an0290, additions, attempting, plugin, an0289, accessing, related, an0288, exe, handle, an0287, detect, det0104, strategy, implemented, dictate, enrollment, deactivation, m1018, disallow, sensitive, m1024, write, m1022, features, light, ppl, integrity, m1025, premises, place, administrator, those, required, dedicated, rather, than, root, users, separation, selinux, grsecurity, apparmor, limiting, escalation, opportunities, well, their, permission, levels, routinely, look, situations, could, allow, gain, wide, obtaining, audits, should, include, been, not, authorized, follow, best, practices, design, administration, tiers, m1026, property, set, unless, there, application, requirements, allowreversiblepasswordencryption, m1027, starting, 22h2, group, winlogon, sending, providers, enablemprnotifications, must, present, installation, computer, entry, notification, system32, operating, m1028, integrating, organizational, greatly, reduce, risk, gaining, initial, lateral, movement, collecting, information, m1032, unknown, key, subkey, pointing, currentc, ontrolset, providerpath, discrepancies, pass, pta, agents, portal, identify, unwanted, unapproved, adfs, executable, assembly, cache, directories, they, note, some, cases, catalog, which, cause, appear, unsigned, when, viewing, properties, logs, enforcement, functioning, intended, m1047, mitigation, create, malicious, config, tortoisesvn, s0692, ssh_login, functions, steal, plaintext, auth_pubkey, s0487, replaced, legitimate, versions, collect, numerous, applications, g1016, intercept, private, function, ssh, add, s0377, intercepted, logged, module, edge, located, dsauth, s9013, included, aaa, c0046, procedure, examples, live, permalink, last, modified, chris, ross, xorrior, contributors, iaas, office, suite, saas, persistence, defense, impairment, maliciously, this, either, reveal, compromised, controls, placed, various, even, persistent, externally, available, vpns, outlook, web, desktop, enable, otherwise, unwarranted, handled, server, manager, sam, unix, based, authorization, plugins, responsible, gathering, storing, validating, able, without, conditional, device, open, join, mclean, hotel, location, details, register, here, search, blog, contribute, benefactors, legal, branding, history, engage, tools, advisory, council, learn, more, about, get, started, detections, technique,
Text of the page (random words):
modify authentication process technique t1556 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise modify authentication process modify authentication process sub techniques 9 id name t1556 001 domain controller authentication t1556 002 password filter dll t1556 003 pluggable authentication modules t1556 004 network device authentication t1556 005 reversible encryption t1556 006 multi factor authentication t1556 007 hybrid identity t1556 008 network provider dll t1556 009 conditional access policies adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts the authentication process is handled by mechanisms such as the local security authentication server lsass process and the security accounts manager sam on windows pluggable authentication modules pam on unix based systems and authorization plugins on macos systems responsible for gathering storing and validating credentials by modifying an authentication process an adversary may be able to authenticate to a service or system without using valid accounts adversaries may maliciously modify a part of this process to either reveal credentials or bypass authentication mechanisms compromised credentials or access may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services such as vpns outlook web access and remote desktop id t1556 sub techniques t1556 001 t1556 002 t1556 003 t1556 004 t1556 005 t1556 006 t1556 007 t1556 008 t1556 009 ⓘ tactics defense impairment persistence credential access ⓘ platforms iaas identity provider linux network devices office suite saas windows macos contributors chris ross xorrior version 3 0 created 11 february 2020 last modified 12 may 2026 version permalink live version procedure examples id name description c0046 arcanedoor arcanedoor included modification of the aaa process to bypass authentication mechanisms 1 s9013 dryhook dryhook has intercepted and logged user credentials by modifying the perl module in ivanti connect secure vpn edge devices located within home perl dsauth pm 2 3 s0377 ebury ebury can intercept private keys using a trojanized ssh add function 4 g1016 fin13 fin13 has replaced legitimate keepass binaries with trojanized versions to collect passwords from numerous applications 5 s0487 kessel kessel has trojanized the ssh_login and user auth_pubkey functions to steal plaintext credentials 6 s0692 silenttrinity silenttrinity can create a backdoor in keepass using a malicious config file and in tortoisesvn using a registry hook 7 mitigations id mitigation description m1047 audit review authentication logs to ensure that mechanisms such as enforcement of mfa are functioning as intended periodically review the hybrid identity solution in use for any discrepancies for example review all pass through authentication pta agents in the azure management portal to identify any unwanted or unapproved ones 8 if adfs is in use review dlls and executable files in the ad fs and global assembly cache directories to ensure that they are signed by microsoft note that in some cases binaries may be catalog signed which may cause the file to appear unsigned when viewing file properties 9 periodically review for new and unknown network provider dlls within the registry hkey_local_machine system currentcontrolset services networkprovidername networkprovider providerpath ensure only valid network provider dlls are registered the name of these can be found in the registry key at hkey_local_machine system currentcontrolset control networkprovider order and have corresponding service subkey pointing to a dll at hkey_local_machine system currentc ontrolset services networkprovidername networkprovider m1032 multi factor authentication integrating multi factor authentication mfa as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access lateral movement and collecting information mfa can also be used to restrict access to cloud resources and apis m1028 operating system configuration ensure only valid password filters are registered filter dlls must be present in windows installation directory c windows system32 by default of a domain controller and or local computer with a corresponding entry in hkey_local_machine system currentcontrolset control lsa notification packages starting in windows 11 22h2 the enablemprnotifications policy can be disabled through group policy or through a configuration service provider to prevent winlogon from sending credentials to network providers 10 m1027 password policies ensure that allowreversiblepasswordencryption property is set to disabled unless there are application requirements 11 m1026 privileged account management audit domain and local accounts as well as their permission levels routinely to look for situations that could allow an adversary to gain wide access by obtaining credentials of a privileged account 12 13 these audits should also include if default accounts have been enabled or if new local accounts are created that have not be authorized follow best practices for design and administration of an enterprise network to limit privileged account use across administrative tiers 14 limit access to the root account and prevent users from modifying protected components through proper privilege separation ex selinux grsecurity apparmor etc and limiting privilege escalation opportunities limit on premises accounts with access to the hybrid identity solution in place for example limit azure ad global administrator accounts to only those required and ensure that these are dedicated cloud only accounts rather than hybrid ones 9 m1025 privileged process integrity enabled features such as protected process light ppl for lsa 15 m1022 restrict file and directory permissions restrict write access to the library security securityagentplugins directory m1024 restrict registry permissions restrict registry permissions to disallow the modification of sensitive registry keys such as hkey_local_machine system currentcontrolset control networkprovider order m1018 user account management ensure that proper policies are implemented to dictate the the secure enrollment and deactivation of authentication mechanisms such as mfa for user accounts detection strategy id name analytic id analytic description det0104 detect modification of authentication processes across platforms an0287 detects modification of lsass and authentication dlls suspicious registry changes to password filter packages and abnormal process access to lsass exe correlates registry modifications dll loads and process handle access events an0288 detects modification of pam configuration files unauthorized new pam modules and suspicious process execution accessing pam related binaries correlates file modification events in etc pam d with process execution of unauthorized binaries an0289 detects unauthorized additions or changes to library security securityagentplugins and suspicious process activity attempting to hook authentication apis correlates file modifications with abnormal plugin loads in authentication flows an0290 detects suspicious configuration changes in idp authentication flows such as enabling reversible password encryption mfa bypass or policy weakening correlates policy modification events with unusual administrative activity an0291 detects unauthorized changes to iam authentication configurations such as disabling mfa creating backdoor access keys or altering trust policies correlates identity policy updates with unusual login behavior references cisco talos 2024 april 24 arcanedoor new espionage focused campaign found targeting perimeter network devices retrieved january 6 2025 john wolfram josh murchie matt lin daniel ainsworth robert wallace dimiter andonov dhanesh kizhakkinan jacob thompson 2025 january 8 ivanti connect secure vpn targeted in new zero day exploitation retrieved april 14 2026 sila ozeren hacioglu 2025 may 5 unc5221 s latest exploit weaponizing cve 2025 22457 in ivanti connect secure retrieved april 13 2026 m léveillé m 2014 february 21 an in depth analysis of linux ebury retrieved april 19 2019 ta v et al 2022 august 8 fin13 a cybercriminal threat actor focused on mexico retrieved february 9 2023 dumont r m léveillé m porcher h 2018 december 1 the dark side of the forsshe a landscape of openssh backdoors retrieved july 16 2020 salvati m 2019 august 6 silenttrinity modules retrieved march 24 2022 mike burns 2020 september 30 detecting microsoft 365 and azure active directory backdoors retrieved september 28 2022 microsoft threat intelligence center microsoft detection and response team microsoft 365 defender research team 2022 august 24 magicweb nobelium s post compromise trick to authenticate as anyone retrieved september 28 2022 microsoft 2023 january 26 policy csp windowslogon retrieved march 30 2023 microsoft 2021 october 28 store passwords using reversible encryption retrieved january 3 2022 microsoft 2016 april 15 attractive accounts for credential theft retrieved june 3 2016 microsoft 2016 april 16 implementing least privilege administrative models retrieved june 3 2016 plett c poggemeyer l 12 october 26 securing privileged access reference material retrieved april 25 2017 microsoft 2013 july 31 configuring additional lsa protection retrieved february 13 2015 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|