Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1621

T1621Multi-Factor Authentication Request Generation

T1621 — Multi-Factor Authentication Request Generation is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 24 detection use cases covering it and 5 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
24Use cases
5Articles
0Sub-techniques
1Tactic

Use cases covering this technique (24)

Cisco Duo fraud-marked push notifications Internal delivery · alerting DD MFA fatigue / push-bombing Internal actions · alerting DSP Okta Authentication Failed During MFA Challenge ESCU actions · alerting P Okta Mismatch Between Source and Response for Verify Push Request ESCU actions · alerting P Okta Multiple Failed MFA Requests For User ESCU actions · hunting P Okta Successful Single Factor Authentication ESCU actions · hunting P PingID Mismatch Auth Source and Verification Response ESCU actions · alerting P PingID Multiple Failed MFA Requests For User ESCU actions · alerting P PingID New MFA Method After Credential Reset ESCU actions · alerting P PingID New MFA Method Registered For User ESCU actions · alerting P ASL AWS Multi-Factor Authentication Disabled ESCU actions · alerting P AWS Console Login Failed During MFA Challenge ESCU actions · alerting P AWS Multi-Factor Authentication Disabled ESCU actions · alerting P AWS Multiple Failed MFA Requests For User ESCU actions · hunting P Azure AD Authentication Failed During MFA Challenge ESCU actions · alerting P Azure AD Multiple Denied MFA Requests For User ESCU actions · alerting P Azure AD Multiple Failed MFA Requests For User ESCU actions · alerting P GCP Authentication Failed During MFA Challenge ESCU actions · alerting P GCP Multiple Failed MFA Requests For User ESCU actions · alerting P O365 Multiple Failed MFA Requests For User ESCU actions · alerting P [LLM] Entra ID MFA fatigue: burst of MFA-challenge failures followed by a successful MFA sign-in Bespoke exploit · alerting DSPDD [LLM] Successful Entra ID device-code authentication (ARToken/EvilTokens PhaaS MFA bypass) Bespoke delivery · hunting DSΣP [LLM] OAuth device-code authorization flow sign-in (ARToken/EvilTokens MFA bypass) Bespoke exploit · hunting DSΣ [LLM] Iran-aligned MFA push-bombing followed by new auth method registered (AA24-290A) Bespoke actions · alerting DSP

Articles citing this technique (5)