Compliance Node Overview
MITRE ATT&CK T1621 (Multi-Factor Authentication Request Generation) is an Enterprise Credential Access technique. Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users. Adversaries in possession of credentials to Valid Accounts may be unable to complete the login process if they lack access to the 2FA or MFA mechanisms required as an additional credential and security control. Affected platforms: Windows, Linux, macOS, IaaS, SaaS, Office Suite, Identity Provider. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1036 Account Use Policies, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-06, CM-05, IA-02, IA-03, IA-05, IA-13.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1621/
SHA-256 integrity: f63dd482a5f0dc05336c7d9e3478f16f3a7aeafe47fb875880861755b3a0c6da
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1621: Multi-Factor Authentication Request Generation (https://attack.mitre.org/techniques/T1621/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access