{
  "node_id": "mitre-attack-t1621-multi-factor-authentication-request-generation",
  "title": "MITRE ATT&CK T1621: Multi-Factor Authentication Request Generation (Enterprise Tactic TA0006 - Credential Access)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1621 (Multi-Factor Authentication Request Generation) is an Enterprise Credential Access technique. Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users. Adversaries in possession of credentials to Valid Accounts may be unable to complete the login process if they lack access to the 2FA or MFA mechanisms required as an additional credential and security control. Affected platforms: Windows, Linux, macOS, IaaS, SaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1036 Account Use Policies, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-06, CM-05, IA-02, IA-03, IA-05, IA-13.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 7
}