Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1111

T1111Multi-Factor Authentication Interception

T1111 — Multi-Factor Authentication Interception is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 3 detection use cases covering it and 4 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
3Use cases
4Articles
0Sub-techniques
1Tactic

Use cases covering this technique (3)

[LLM] AiTM MFA-relay: successful Entra sign-in from AWS EC2 / hosting ASN Bespoke actions · hunting DSPDD [LLM] JWR real-time exfil & operator WebSocket channel (the_final_interface / addCvv / webSocket/QT) Bespoke c2 · alerting DSΣP [LLM] AitM session hijack: PaaS phishing-page visit followed by successful Entra sign-in from a different IP Bespoke actions · alerting DS

Articles citing this technique (4)