Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1621

T1621Multi-Factor Authentication Request Generation

T1621 — Multi-Factor Authentication Request Generation is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 22 detection use cases covering it and 2 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
22Use cases
2Articles
0Sub-techniques
1Tactic

Use cases covering this technique (22)

Cisco Duo fraud-marked push notifications Internal delivery · alerting DD MFA fatigue / push-bombing Internal actions · alerting DSP Okta Authentication Failed During MFA Challenge ESCU actions · alerting P Okta Mismatch Between Source and Response for Verify Push Request ESCU actions · alerting P Okta Multiple Failed MFA Requests For User ESCU actions · hunting P Okta Successful Single Factor Authentication ESCU actions · hunting P PingID Mismatch Auth Source and Verification Response ESCU actions · alerting P PingID Multiple Failed MFA Requests For User ESCU actions · alerting P PingID New MFA Method After Credential Reset ESCU actions · alerting P PingID New MFA Method Registered For User ESCU actions · alerting P ASL AWS Multi-Factor Authentication Disabled ESCU actions · alerting P AWS Console Login Failed During MFA Challenge ESCU actions · alerting P AWS Multi-Factor Authentication Disabled ESCU actions · alerting P AWS Multiple Failed MFA Requests For User ESCU actions · hunting P Azure AD Authentication Failed During MFA Challenge ESCU actions · alerting P Azure AD Multiple Denied MFA Requests For User ESCU actions · alerting P Azure AD Multiple Failed MFA Requests For User ESCU actions · alerting P GCP Authentication Failed During MFA Challenge ESCU actions · alerting P GCP Multiple Failed MFA Requests For User ESCU actions · alerting P O365 Multiple Failed MFA Requests For User ESCU actions · alerting P [LLM] MFA approval within minutes of inbound external Microsoft Teams chat Bespoke exploit · alerting DSPDDCS [LLM] Iran-aligned MFA push-bombing followed by new auth method registered (AA24-290A) Bespoke actions · alerting DSP

Articles citing this technique (2)