MITRE ATT&CK technique
Modify Authentication Process detection rulesT1556
Modify Authentication Process (T1556) is a MITRE ATT&CK technique in the Credential Access tactic. This page lists the 19 community-maintained Sigma detection rules in the library mapped to T1556 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target azure, windows, aws.
AWS Identity Center Identity Provider Change
highDetects a change in the AWS Identity Center (FKA AWS SSO) identity provider. A change in identity provider allows an attacker to establish persistent access or escalate privileges via user impersonation.
aws
Directory Service Restore Mode(DSRM) Registry Value Tampering
highDetects changes to "DsrmAdminLogonBehavior" registry value. During a Domain Controller (DC) promotion, administrators create a Directory Services Restore Mode (DSRM) local administrator account with a password that rarely changes. The DSRM account is an “Administrator” account that logs in with the DSRM mode when the server is booting up to restore AD backups or recover the server from a failure. Attackers could abuse DSRM account to maintain their persistence and access to the organization's Active Directory. If the "DsrmAdminLogonBehavior" value is set to "0", the administrator account can only be used if the DC starts in DSRM. If the "DsrmAdminLogonBehavior" value is set to "1", the administrator account can only be used if the local AD DS service is stopped. If the "DsrmAdminLogonBehavior" value is set to "2", the administrator account can always be used.
windows · registry_set
Disabling Multi Factor Authentication
highDetects disabling of Multi Factor Authentication.
m365
Github High Risk Configuration Disabled
highDetects when a user disables a critical security feature for an organization.
github
Possible Shadow Credentials Added
highDetects possible addition of shadow credentials to an active directory object.
windows
Powershell Install a DLL in System Directory
highUses PowerShell to install/copy a file into a system directory such as "System32" or "SysWOW64"
windows · ps_script
CA Policy Removed by Non Approved Actor
mediumMonitor and alert on conditional access changes where non approved actor removed CA Policy.
azure
CA Policy Updated by Non Approved Actor
mediumMonitor and alert on conditional access changes. Is Initiated by (actor) approved to make changes? Review Modified Properties and compare "old" vs "new" value.
azure
Certificate-Based Authentication Enabled
mediumDetects when certificate based authentication has been enabled in an Azure Active Directory tenant.
azure
Change to Authentication Method
mediumChange to authentication method could be an indicator of an attacker adding an auth method to the account so they can have continued access.
azure
Cisco Dot1x Disabled
mediumDetects the manual disablement of IEEE 802.1X (dot1x) on a Cisco network device interface. Disabling dot1x bypasses Network Access Control (NAC) mechanisms, potentially allowing unauthorized devices to gain access to the internal network. This activity is a common technique used by attackers or malicious insiders to establish persistence or perform lateral movement via rogue devices.
cisco
Disabled MFA to Bypass Authentication Mechanisms
mediumDetection for when multi factor authentication has been disabled, which might indicate a malicious activity to bypass authentication mechanisms.
azure
Dropping Of Password Filter DLL
mediumDetects dropping of dll files in system32 that may be used to retrieve user credentials from LSASS
windows · process_creation
New Root Certificate Authority Added
mediumDetects newly added root certificate authority to an AzureAD tenant to support certificate based authentication.
azure
Okta MFA Reset or Deactivated
mediumDetects when an attempt at deactivating or resetting MFA.
okta
Potential Suspicious Activity Using SeCEdit
mediumDetects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy
windows · process_creation
User Added To Group With CA Policy Modification Access
mediumMonitor and alert on group membership additions of groups that have CA policy modification access
azure
User Removed From Group With CA Policy Modification Access
mediumMonitor and alert on group membership removal of groups that have CA policy modification access
azure
Azure AD Only Single Factor Authentication Required
lowDetect when users are authenticating without MFA being required.
azure