Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0160 — Detection Strategy for Multi-Factor Authentication Request Generation (T1621)
DET0160

Detection Strategy for Multi-Factor Authentication Request Generation (T1621)

6 analytic(s) · 1 technique(s) detected

Analytics

6
AN0449 Analytic 0449
Identity Provider

Monitor for excessive or anomalous MFA push notifications or token requests, especially when login attempts originate from unusual IPs or geolocations and do not correspond to legitimate user-initiated sessions.

azure:signinlogs Multiple MFA challenge requests without successful primary login NSM:Connections PushNotificationSent
[TimeWindow] Threshold of MFA prompts per user within a short time period
[GeoIPAllowList] Expected login locations for workforce; deviations can be tuned
AN0450 Analytic 0450
IaaS

Detect abnormal MFA activity within cloud service provider logs, such as repeated generation of MFA challenges for the same user session or mismatched MFA device and login origin.

AWS:CloudTrail AssumeRole or ConsoleLogin with repeated MFA failures followed by repeated MFA requests
[FailedLoginThreshold] Number of failed logins before raising detection
AN0451 Analytic 0451
Windows

Detect repeated failed login events followed by MFA challenges triggered in rapid succession, especially if originating from service accounts or anomalous IP addresses.

WinEventLog:Security EventCode=4625
[ServiceAccountExclusion] Exclude specific accounts where automated MFA requests are legitimate
AN0452 Analytic 0452
Linux

Monitor PAM and syslog entries for unusual frequency of login attempts that trigger MFA prompts, particularly when MFA challenges do not match expected user behavior.

auditd:AUTH pam_unix or pam_google_authenticator invoked repeatedly within short interval
[AuthRetryThreshold] Number of retries per user allowed before detection is triggered
AN0453 Analytic 0453
SaaS

Detect anomalous OAuth or SSO logins that repeatedly generate MFA challenges, particularly where MFA approvals are denied or timed out by the user.

saas:okta MFAChallengeIssued
[MFAProvider] Identify which MFA service provider logs are in use (Okta, Duo, Microsoft Authenticator)
AN0454 Analytic 0454
macOS

Detect user account logon attempts that trigger multiple MFA challenges through enterprise identity integrations, especially if MFA push requests are generated without successful interactive login.

macos:unifiedlog authd generating multiple MFA token requests
[DeviceEnrollmentStatus] Exclude unmanaged macOS devices that use different MFA providers

Detected Techniques

1

Details

MITRE ID
DET0160
STIX ID
x-mitre-detection-strategy--5dab1bc7-89e2-4fe4-ae30-40b550d0daf4
Analytics
6
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.