Compliance Node Overview
MITRE ATT&CK T1649 (Steal or Forge Authentication Certificates) is an Enterprise Credential Access technique. Adversaries may steal or forge certificates used for authentication to access remote systems or resources. Digital certificates are often used to sign and encrypt messages and/or files. Certificates are also used as authentication material. For example, Entra ID device certificates and Active Directory Certificate Services (AD CS) certificates bind to an identity and can be used as credentials for domain accounts. Authentication certificates can be both stolen and forged. Affected platforms: Windows, Linux, macOS, Identity Provider. MITRE-documented mitigations include M1015 Active Directory Configuration, M1042 Disable or Remove Feature or Program, M1041 Encrypt Sensitive Information, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls IA-02, IA-05, IA-13.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1649/
SHA-256 integrity: 425cbf7e558e9d1f471b2fd1851ec411634080c0d69e995816dd2fc4dd9c716a
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1649: Steal or Forge Authentication Certificates (https://attack.mitre.org/techniques/T1649/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.