Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1556

T1556Modify Authentication Process

T1556 — Modify Authentication Process is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 53 detection use cases covering it and 11 threat-intel articles citing it.

Defense EvasionPersistenceCredential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
53Use cases
11Articles
9Sub-techniques
3Tactics

Sub-techniques (9)

Use cases covering this technique (53)

JWT authentication bypass attempt Internal delivery · alerting DD Auth0 breached-password detection disabled Internal install · alerting DD Auth0 brute-force protection disabled Internal install · alerting DD Auth0 suspicious-IP throttling disabled Internal install · alerting DD Azure AD MFA disabled for a user Internal install · alerting DD Confluence global security setting changed Internal install · alerting DD Datadog organization login method changed Internal install · alerting DD Cisco Duo emergency bypass code created Internal install · alerting DD GitHub organization 2FA requirement removed Internal install · alerting DD GitHub SAML/OIDC SSO disabled Internal install · alerting DD GitLab user MFA disabled Internal install · alerting DD GitLab password reset from suspicious IP Internal delivery · alerting DD GitLab SSO disabled Internal install · alerting DD Google Workspace admin disabled 2SV for OU Internal install · alerting DD Google Workspace user disabled 2SV on own account Internal install · alerting DD M365 MFA disabled for a user Internal install · alerting DD MongoDB authentication disabled Internal install · alerting DD Okta authentication / sign-on policy modified Internal install · alerting DD Okta MFA bypass attempt Internal delivery · alerting DD PostgreSQL authentication method modified Internal install · alerting DD [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Internal exploit · alerting DSPDDCW Cisco Duo Admin Login Unusual Browser ESCU actions · alerting P Cisco Duo Admin Login Unusual Country ESCU actions · alerting P Cisco Duo Admin Login Unusual Os ESCU actions · alerting P Cisco Duo Bulk Policy Deletion ESCU actions · alerting P Cisco Duo Bypass Code Generation ESCU actions · alerting P Cisco Duo Policy Allow Devices Without Screen Lock ESCU actions · alerting P Cisco Duo Policy Allow Network Bypass 2FA ESCU actions · alerting P Cisco Duo Policy Allow Old Flash ESCU actions · alerting P Cisco Duo Policy Allow Old Java ESCU actions · alerting P Cisco Duo Policy Allow Tampered Devices ESCU actions · alerting P Cisco Duo Policy Bypass 2FA ESCU actions · alerting P Cisco Duo Policy Deny Access ESCU actions · alerting P Cisco Duo Policy Skip 2FA for Other Countries ESCU actions · alerting P Cisco Duo Set User Status to Bypass 2FA ESCU actions · alerting P Okta Phishing Detection with FastPass Origin Check ESCU actions · alerting P O365 Disable MFA ESCU actions · alerting P O365 Excessive SSO logon errors ESCU actions · hunting P Disabling Windows Local Security Authority Defences via Registry ESCU actions · alerting P Cisco Network Interface Modifications ESCU actions · hunting P [LLM] OWAReaper server-side persistence: Owner rights granted to 'Default' user on mailbox folders Bespoke install · alerting DSΣP [LLM] Check Point SmartConsole admin login via forged application token (CVE-2026-16232) Bespoke exploit · hunting SΣP [LLM] Pheditor forced-password-change auth bypass — POST to pheditor.php Bespoke exploit · hunting SΣP [LLM] Auth.js server-configuration error reaching production (fail-open precondition) Bespoke exploit · alerting SΣPDDCW [LLM] Auth.js fail-open exploited: protected routes served 200/302 during an active auth-error window Bespoke exploit · hunting SP [LLM] Auth.js config break on deploy: first-ever [auth][error] on a previously-healthy host Bespoke exploit · alerting SP [LLM] FileBrowser proxy-auth header forgery naming admin on /api/login Bespoke exploit · alerting SΣPDD [LLM] Langroid Neo4jChatAgent launched with allow_dangerous_operations enabled Bespoke install · hunting DSPDDCS [LLM] FortiGate jsconsole / loopback admin login (CVE-2024-55591 auth-bypass exploitation) Bespoke exploit · alerting SP [LLM] phpBB password-reset host-header poisoning (CVE-2026-29199) Bespoke exploit · hunting SP [LLM] Qinglong CVE-2026-3965 auth bypass via /open/user/init credential reset Bespoke exploit · alerting DSΣPDDCS [LLM] BodySnatcher (CVE-2025-12420) ServiceNow Virtual Agent bot/integration exploit Bespoke exploit · alerting SΣP [LLM] Next.js CVE-2025-29927 middleware bypass via x-middleware-subrequest header Bespoke exploit · alerting DSΣPDDCS

Articles citing this technique (11)