Modify Authentication Process T1556

Tactics: Defense Impairment, Persistence, Credential Access

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Events covered

21 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 169 rules share fields, values, and exclusions.

Fields filtered most (193 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType32eq 23, in 10exec, modification, ProcessRollup2, exec_event, user risk detection
data_stream.dataset27eq 26, in 1okta.system, aws.cloudtrail, azure.auditlogs, azure.identity_protection, azure.signinlogs
sourcetype26eq 26cisco:duo:administrator, cisco:duo:activity, aws:asl, aws:cloudtrail, azure:monitor:aad
action21eq 17, contains 2, in 2policy_create, policy_update, disblmfa, UpdateIPRestrictions, UpdateLoginSettings
host.os.type17eq 17
event.outcome13eq 13success
event.type11eq 11start, change, creation, end
EventID10eq 9, in 124, 4103, 4104, 4688, 4723
process_name9eq 5, in 5, is_not_null 1, starts_with 1sshd, ssh, ., azureadconnectauthenticationagentservice.exe, bash
OperationName8eq 5, contains 3, in 2Add member to group, Add named location, Delete conditional access policy, add service principal, admin deleted security info
TargetFilename7starts_with 3, wildcard 3, contains 1, ends_with 1, eq 1, in 1, match 1*/.vscode/extensions/*mcp*, */appdata/roaming/cursor/*mcp*, /.claude/, /boot/efi/efi/*/grub.cfg, /boot/grub/grub.cfg
eventType7eq 5, contains 1, in 1application.lifecycle.update, user.authentication.auth_via_mfa, application.lifecycle.activate, application.lifecycle.create, system.idp.lifecycle
type7eq 7, starts_with 1TAILNET, 2sv_change, IdentityProvider, POSTURE, POSTURE_INTEGRATION
Image6is_not_null 2, starts_with 2, ends_with 1, wildcard 1./, ./*, /bin/, /boot/, /boot/*
Provider_Name6eq 6iam.amazonaws.com, rds.amazonaws.com, rolesanywhere.amazonaws.com, sts.amazonaws.com

Top indicator values (809 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
13375
sourcetypeeq
cisco:duo:administrator
1010
sourcetypeeq
cisco:duo:activity
44
data_stream.dataseteq
okta.system
948
data_stream.dataseteq
aws.cloudtrail
6173
data_stream.dataseteq
azure.auditlogs
426
actioneq
policy_create
88
actioneq
policy_update
89
event.typeeq
start
61087
event.typeeq
change
395
event.typeeq
creation
352
Actioneq
UPDATE
44
EventTypeeq
exec
4579
EventTypeeq
modification
272
typeeq
TAILNET
44
Provider_Nameeq
iam.amazonaws.com
332
action.nameeq
admin_login
33
log_sourceeq
auditevents
312
AppNamestarts_with
ConnectSyncProvisioning_
22
AttributeLDAPDisplayNameeq
msds-keycredentiallink
22
Categoryeq
usermanagement
211
EventTypein
ProcessRollup2
2118
EventTypein
exec
2206
EventTypein
exec_event
2150
OldCredentialNamescross_field_compare
NewCredentialNames
2
TargetObjectwildcard
hklm\system\*controlset*\services\*\networkprovider\providerpath
22
aws::eventNameeq
createvirtualmfadevice
22
aws::eventNameeq
deactivatemfadevice
22
aws::eventNameeq
deletevirtualmfadevice
22
azure_ad::authentication_requirementeq
singlefactorauthentication
28

Exclusions (399 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Detailseq
?:\program files (x86)\citrix\ica client\x64\pnsson.dll
2
Imagein
./usr/bin/podman
2
Imagein
/bin/autossl_check
2
Imagein
/bin/chef-client
2
Imagein
/bin/dnf
2
Imagein
/bin/dnf-automatic
2
Imagein
/bin/dockerd
2
Imagein
/bin/dpkg
2
Imagein
/bin/dpkg-divert
2
Imagein
/bin/microdnf
2
Imagein
/bin/pacman
2
Imagein
/bin/pamac-daemon
2
Imagein
/bin/podman
2
Imagein
/bin/puppet
2
Imagein
/bin/rpm
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 20 rules

Elastic 46 rules

Splunk 35 rules

Kusto 32 rules

YARA-L 5 rules

Panther 31 rules