Compliance Node Overview
MITRE ATT&CK T1556.003 (Pluggable Authentication Modules) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts. PAM is a modular system of configuration files, libraries, and executable files which guide authentication for many services. The most common authentication module is pam_unix.so, which retrieves, sets, and verifies account authentication information in /etc/passwd and /etc/shadow. Adversaries may modify components of the PAM system to create backdoors. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-07, AC-20, CA-07, CM-02.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1556/003/
SHA-256 integrity: 5d56eac220489a1ca76799370482207c2c6427788847c9924cd1e6574fc15a28
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1556.003: Pluggable Authentication Modules (https://attack.mitre.org/techniques/T1556/003/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access