T1556: T1556
Essential information
- MITRE technique ID
T1556- Confidence
- 100/100
- Revoked
- No
- Published
- 11/02/2020 20:01
- Modified
- 27/03/2026 01:12
- Author / Source
- The MITRE Corporation
Aliases
Modify Authentication Process
Platforms
windows macos linux Network Devices IaaS Office Suite Identity Provider SaaS
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | credential-access |
| mitre-attack | defense-evasion |
| mitre-attack | persistence |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (17)
-
The MITRE Corporation Confidence 100
[FIN13](https://attack.mitre.org/groups/G1016) is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. [FIN13](https://attack.mitre.org/groups/G1016) achieves…
First seen 01/01/1970 · Last seen 16/11/5138 · -
UNC5221 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed…
First seen 01/01/1970 · Last seen 16/11/5138 · -
NullBulge relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (67)
-
W32.File.MalParent usesFamily
-
VSingle uses
-
GREASE usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Knight usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Meterpreter usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Spider Threat uses
-
WIREFIRE - S1115 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
BianLian usesFamily
-
BEEFLUSH usesFamily
-
Rockstar 2FA uses
-
Medusa usesThe MITRE Corporation Confidence 100
[MEDUSA](https://attack.mitre.org/software/S1220) is an open-source rootkit that is capable of dynamic linker hijacking, command execution, and logging credentials.(Citation: Google Cloud Mandiant UNC3886 2024)
First seen 01/01/1970 · Last seen 16/11/5138 · -
WorkersDevBackdoor usesFamily
Reports (20)
-
14 MITREs 2 Malwares 51 Observables
-
Uncovering Espionage Operations related5 CVEs 14 MITREs 7 Malwares 39 Observables 1 APT
-
20 MITREs 6 Malwares 19 Observables 1 APT
-
1 CVE 20 MITREs 4 Malwares 14 Observables 1 APT
-
LightSpy: Implant for macOS related2 CVEs 9 MITREs 43 Observables
-
12 MITREs 30 Observables
-
13 MITREs 6 Malwares 4 Observables 1 APT
-
8 MITREs 2 Malwares 13 Observables
Vulnerabilities (CVE) (51)
When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource …
- Attack vector
- NETWORK
- Published
- 15/10/2025
- Modified
- 21/12/2025
VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail …
- Attack vector
- Local
- Published
- 23/06/2023
- Modified
- 21/12/2025
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway …
- Attack vector
- Network
- Published
- 18/10/2023
- Modified
- 21/12/2025
Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can …
- Attack vector
- Network
- Published
- 09/10/2024
- Modified
- 21/12/2025
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker …
- Attack vector
- Network
- Published
- 16/10/2023
- Modified
- 21/12/2025
When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic …
- Attack vector
- NETWORK
- Published
- 15/10/2025
- Modified
- 21/12/2025
When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON …
- Attack vector
- NETWORK
- Published
- 15/10/2025
- Modified
- 21/12/2025
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges …
- Attack vector
- Network
- Published
- 12/04/2024
- Modified
- 21/12/2025
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …
- Attack vector
- LOCAL
- Published
- 22/11/2024
- Modified
- 21/12/2025
When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd …
- Attack vector
- NETWORK
- Published
- 15/10/2025
- Modified
- 21/12/2025
A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges. A …
- Attack vector
- LOCAL
- Published
- 15/10/2025
- Modified
- 21/12/2025
Attack patterns (MITRE) (8)
-
T1556.001 subtechnique-ofDomain Controller Authentication MITRE
-
Network Device Authentication subtechnique-ofT1556.004 MITRE
-
Network Provider DLL subtechnique-of
-
Multi-Factor Authentication subtechnique-of
-
T1556.002 subtechnique-ofPassword Filter DLL MITRE
-
Hybrid Identity subtechnique-of
-
Conditional Access Policies subtechnique-of
-
Pluggable Authentication Modules subtechnique-ofT1556.003 MITRE
Course Of Action (7)
-
Audit mitigates
-
Operating System Configuration mitigates
-
Restrict Registry Permissions mitigates
-
Restrict File and Directory Permissions mitigates
-
Multi-factor Authentication mitigates
-
Privileged Account Management mitigates
-
Privileged Process Integrity mitigates
Campaign (1)
-
ArcaneDoor uses
Tool (1)
-
SILENTTRINITY usesThe MITRE Corporation Confidence 100
[SILENTTRINITY](https://attack.mitre.org/software/S0692) is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers written in Powershell, C, and Boo. [SILENTTRINITY](https://attack.mitre.org/software/S0692) was used in a…