What MITRE ATT&CK T1556.006: Multi-Factor Authentication (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence) requires
MITRE ATT&CK T1556.006 (Multi-Factor Authentication) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts. Once adversaries have gained access to a network by either compromising an account lacking MFA or by employing an MFA bypass method such as Multi-Factor Authentication Request Generation, adversaries may leverage their access to modify or completely disable MFA defenses. Affected platforms: Windows, SaaS, IaaS, Linux, macOS, Office Suite, Identity Provider. MITRE-documented mitigations include M1018 User Account Management, M1047 Audit, M1032 Multi-factor Authentication. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-07, AC-20, CA-07, CM-02.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1556/006/
SHA-256 integrity: 2120c95386e5c1de2238c113ac779b19a6ff32cc94b5a0b76700c691d7cadc24
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1556.006: Multi-Factor Authentication (https://attack.mitre.org/techniques/T1556/006/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access