T1556 Modify Authentication Process — Detection & Response
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSAS) on Windows or Pluggable Authentication Modules (PAM) on Unix-based systems.
Coverage at a glance
- Detections shipped
- 3
- Avg. verdict time
- < 5 min
- Data sources
- 3+
Threat context
How adversaries use T1556 Modify Authentication Process — Detection & Response
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSAS) on Windows or Pluggable Authentication Modules (PAM) on Unix-based systems.
MFA modification (T1556.006) is an increasingly observed technique where attackers with admin access register their own MFA factors (authenticator apps, phone numbers) to an existing account, establishing persistent access that survives password resets. Hybrid Identity attacks (T1556.007) exploit federated identity configurations — the Golden SAML technique forges SAML assertions using the AD FS token-signing certificate, enabling persistent access to cloud services without authenticating against the on-premises identity provider.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| New MFA Factor Registered for High-Privilege User — Admin account adds new authenticator A privileged user registers a new MFA factor from an unrecognised device or unusual location. | Critical | Okta / Entra ID |
| SAML Token Signing Certificate Accessed — AD FS certificate private key read The AD FS token signing certificate private key is accessed, enabling Golden SAML token forgery. | Critical | Windows Event Log / CrowdStrike |
| SAML Provider Modified in AWS — UpdateSAMLProvider API call The SAML identity provider configuration in AWS IAM is modified, potentially replacing it with an attacker-controlled IdP. | High | AWS CloudTrail |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1539 Steal Web Session Cookie — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response: frequently asked questions
What is Golden SAML and how does ManySignal detect it?
Golden SAML is an attack where the adversary steals the AD FS token signing certificate and uses it to forge SAML assertions for any user, including admins. ManySignal detects the certificate access event on the AD FS server (via EDR telemetry) and correlates with subsequent anomalous sign-ins to cloud services.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.