Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK T1556.001: Domain Controller Authentication (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence)

MITRE ATT&CK T1556.001 (Domain Controller Authentication) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556…

What MITRE ATT&CK T1556.001: Domain Controller Authentication (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence) requires

MITRE ATT&CK T1556.001 (Domain Controller Authentication) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may patch the authentication process on a domain controller to bypass the typical authentication mechanisms and enable access to accounts. Malware may be used to inject false credentials into the authentication process on a domain controller with the intent of creating a backdoor used to access any user's account and/or credentials (ex: Skeleton Key). Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1025 Privileged Process Integrity, M1032 Multi-factor Authentication, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-07, AC-20, CA-07, CM-02.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T1556/001/

SHA-256 integrity: d570a9e3f7dd870db73a8510b9f80db294a4bc6168b6b844fa2ef3a63c22a01f

Primary Citations — 7 traced to source

  • MITRE ATT&CK Technique T1556.001: Domain Controller Authentication (https://attack.mitre.org/techniques/T1556/001/)
  • MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.