1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1621 Multi-Factor Authentication Request Generation — Detection Rules

Detection workspace for T1621 Multi-Factor Authentication Request Generation: 2 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1621 Multi-Factor Authentication Request Generation

COUNT(mfa_challenge BY account, 10m) >= threshold OR COUNT(mfa_denied BY account, 10m) >= threshold -> ALERT

Anomaly models

ATT&CK analytic guidance

DET0160 Detection Strategy for Multi-Factor Authentication Request Generation (T1621)

AN0449 Analytic 0449

Monitor for excessive or anomalous MFA push notifications or token requests, especially when login attempts originate from unusual IPs or geolocations and do not correspond to legitimate user-initiated sessions.

AN0450 Analytic 0450

Detect abnormal MFA activity within cloud service provider logs, such as repeated generation of MFA challenges for the same user session or mismatched MFA device and login origin.

AN0451 Analytic 0451

Detect repeated failed login events followed by MFA challenges triggered in rapid succession, especially if originating from service accounts or anomalous IP addresses.

AN0452 Analytic 0452

Monitor PAM and syslog entries for unusual frequency of login attempts that trigger MFA prompts, particularly when MFA challenges do not match expected user behavior.

AN0453 Analytic 0453

Detect anomalous OAuth or SSO logins that repeatedly generate MFA challenges, particularly where MFA approvals are denied or timed out by the user.

AN0454 Analytic 0454

Detect user account logon attempts that trigger multiple MFA challenges through enterprise identity integrations, especially if MFA push requests are generated without successful interactive login.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1621 simulation workspace

No reviewed association in this snapshot.

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.