1200KM / detection
T1556 Modify Authentication Process — Detection Rules
Detection workspace for T1556 Modify Authentication Process: 12 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Github High Risk Configuration Disabled · test · high · {"product":"github","service":"audit","definition":"Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"}
- AWS Identity Center Identity Provider Change · test · high · {"product":"aws","service":"cloudtrail"}
- Disabled MFA to Bypass Authentication Mechanisms · test · medium · {"product":"azure","service":"activitylogs"}
- CA Policy Removed by Non Approved Actor · test · medium · {"product":"azure","service":"auditlogs"}
- CA Policy Updated by Non Approved Actor · test · medium · {"product":"azure","service":"auditlogs"}
- Certificate-Based Authentication Enabled · test · medium · {"product":"azure","service":"auditlogs"}
- New Root Certificate Authority Added · test · medium · {"product":"azure","service":"auditlogs"}
- Change to Authentication Method · test · medium · {"product":"azure","service":"auditlogs"}
- User Added To Group With CA Policy Modification Access · test · medium · {"product":"azure","service":"auditlogs"}
- User Removed From Group With CA Policy Modification Access · test · medium · {"product":"azure","service":"auditlogs"}
- Possible Shadow Credentials Added · test · high · {"product":"windows","service":"security","definition":"The \"Audit Directory Service Changes\" logging policy must be configured in order to receive events. Audit events are generated only for objects with configured system access control lists (SACLs). Audit events are generated only for objects with configured system access control lists (SACLs) and only when accessed in a manner that matches their SACL settings. This policy covers the following events ids - 5136, 5137, 5138, 5139, 5141. Note that the default policy does not cover User objects. For that a custom AuditRule need to be setup (See https://github.com/OTRF/Set-AuditRule)"}
- Directory Service Restore Mode(DSRM) Registry Value Tampering · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0104 Detect Modification of Authentication Processes Across Platforms
AN0287 Analytic 0287
Detects modification of LSASS and authentication DLLs, suspicious registry changes to password filter packages, and abnormal process access to lsass.exe. Correlates registry modifications, DLL loads, and process handle access events.
AN0288 Analytic 0288
Detects modification of PAM configuration files, unauthorized new PAM modules, and suspicious process execution accessing PAM-related binaries. Correlates file modification events in /etc/pam.d/ with process execution of unauthorized binaries.
AN0289 Analytic 0289
Detects unauthorized additions or changes to /Library/Security/SecurityAgentPlugins and suspicious process activity attempting to hook authentication APIs. Correlates file modifications with abnormal plugin loads in authentication flows.
AN0290 Analytic 0290
Detects suspicious configuration changes in IdP authentication flows such as enabling reversible password encryption, MFA bypass, or policy weakening. Correlates policy modification events with unusual administrative activity.
AN0291 Analytic 0291
Detects unauthorized changes to IAM authentication configurations such as disabling MFA, creating backdoor access keys, or altering trust policies. Correlates identity policy updates with unusual login behavior.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.