Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0293 — Detect Hybrid Identity Authentication Process Modification
DET0293

Detect Hybrid Identity Authentication Process Modification

5 analytic(s) · 1 technique(s) detected

Analytics

5
AN0814 Analytic 0814
Windows

Detects injection or tampering of DLLs in hybrid identity agents (e.g., AzureADConnectAuthenticationAgentService), registry or configuration changes tied to PTA/AD FS, and anomalous LSASS or AD FS module loads correlated with authentication anomalies.

WinEventLog:Sysmon EventCode=7 WinEventLog:Security EventCode=5136 WinEventLog:Security Anomalous logon without MFA enforcement
[WatchedServices] Hybrid identity services monitored for tampering, e.g., PTA agent, AD FS.
[TimeWindow] Window correlating DLL/module load events with logon anomalies.
AN0815 Analytic 0815
Identity Provider

Detects registration of new PTA agents, conditional access changes disabling hybrid MFA enforcement, or suspicious updates to AD FS token-signing configurations.

azure:signinlogs Register PTA Agent or Modify AD FS trust m365:unified New agent registration by non-admin user
[PrivilegedRoles] Roles authorized to configure PTA/AD FS integrations.
AN0816 Analytic 0816
IaaS

Detects API calls registering or updating hybrid identity connectors, modification of cloud-to-on-premises federation trust, and unusual token issuance logs.

AWS:CloudTrail UpdateFederationSettings or RegisterHybridConnector
[MonitoredFederations] Federation trusts and connectors relevant to hybrid identity setup.
AN0817 Analytic 0817
Office Suite

Detects tenant-wide authentication or conditional access changes that weaken hybrid identity enforcement, including disabling AD FS or bypassing hybrid MFA policies.

m365:unified Modify Federation Settings or Update Authentication Policy
[PolicyScope] Scope of authentication and federation policies to be monitored.
AN0818 Analytic 0818
SaaS

Detects suspicious changes to SAML/OAuth federation configurations, such as new signing certificates, altered endpoints, or claims issuance rules granting elevated privileges.

saas:okta Federation configuration update or signing certificate change
[FederationEndpoints] Federation/SAML endpoints monitored for modification.

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0293
STIX ID
x-mitre-detection-strategy--6b681059-99f7-46ff-bd36-96fd414074d4
Analytics
5
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.