Compliance Node Overview
MITRE ATT&CK T1111 (Multi-Factor Authentication Interception) is an Enterprise Credential Access technique. Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources. Use of MFA is recommended and provides a higher level of security than usernames and passwords alone, but organizations should be aware of techniques that could be used to intercept and bypass these security mechanisms. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-20, CA-07, CM-02, CM-06, IA-02, IA-05, IA-13, SI-03.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1111/
SHA-256 integrity: 10db97b460f1e10bff2292a30767c4844333e737028fd85fb1d5648e6cbe031d
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1111: Multi-Factor Authentication Interception (https://attack.mitre.org/techniques/T1111/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access