// MITRE ATT&CK
T1556 · Modify Authentication Process
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) ...
¿Cómo detectarlo y mitigarlo?
La detección de Modify Authentication Process parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (9)
T1556.001
Domain Controller Authentication T1556.002
Password Filter DLL T1556.003
Pluggable Authentication Modules T1556.004
Network Device Authentication T1556.005
Reversible Encryption T1556.006
Multi-Factor Authentication T1556.007
Hybrid Identity T1556.008
Network Provider DLL T1556.009
Conditional Access Policies
Domain Controller Authentication T1556.002
Password Filter DLL T1556.003
Pluggable Authentication Modules T1556.004
Network Device Authentication T1556.005
Reversible Encryption T1556.006
Multi-Factor Authentication T1556.007
Hybrid Identity T1556.008
Network Provider DLL T1556.009
Conditional Access Policies
Técnicas relacionadas
T1687
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.003
Modify or Spoof Tool UI T1685.001
Disable or Modify Windows Event Log T1578
Modify Cloud Compute Infrastructure
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.003
Modify or Spoof Tool UI T1685.001
Disable or Modify Windows Event Log T1578
Modify Cloud Compute Infrastructure
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.