MITRE ATT&CK technique
Multi-Factor Authentication Request Generation detection rulesT1621
Multi-Factor Authentication Request Generation (T1621) is a MITRE ATT&CK technique in the Credential Access tactic. This page lists the 2 community-maintained Sigma detection rules in the library mapped to T1621 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target azure.
T1621 on attack.mitre.org2 rules
Top products
Tactic
Multifactor Authentication Denied
mediumUser has indicated they haven't instigated the MFA prompt and could indicate an attacker has the password for the account.
azure
Multifactor Authentication Interrupted
mediumIdentifies user login with multifactor authentication failures, which might be an indication an attacker has the password for the account but can't pass the MFA challenge.
azure