Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0104 — Detect Modification of Authentication Processes Across Platforms
DET0104

Detect Modification of Authentication Processes Across Platforms

5 analytic(s) · 1 technique(s) detected

Analytics

5
AN0287 Analytic 0287
Windows

Detects modification of LSASS and authentication DLLs, suspicious registry changes to password filter packages, and abnormal process access to lsass.exe. Correlates registry modifications, DLL loads, and process handle access events.

WinEventLog:Security EventCode=4657 WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=7
[MonitoredRegistryKeys] Specific LSASS and password filter registry paths monitored for modification.
[TimeWindow] Correlation window between registry change, DLL load, and lsass.exe access.
AN0288 Analytic 0288
Linux

Detects modification of PAM configuration files, unauthorized new PAM modules, and suspicious process execution accessing PAM-related binaries. Correlates file modification events in /etc/pam.d/ with process execution of unauthorized binaries.

auditd:SYSCALL open, write auditd:SYSCALL execve
[WatchedPaths] Critical PAM directories and configuration files monitored for modification.
AN0289 Analytic 0289
macOS

Detects unauthorized additions or changes to /Library/Security/SecurityAgentPlugins and suspicious process activity attempting to hook authentication APIs. Correlates file modifications with abnormal plugin loads in authentication flows.

macos:unifiedlog SecurityAgentPlugins modification macos:osquery process_open
[PluginPaths] List of approved authentication plugin directories to baseline.
AN0290 Analytic 0290
Identity Provider

Detects suspicious configuration changes in IdP authentication flows such as enabling reversible password encryption, MFA bypass, or policy weakening. Correlates policy modification events with unusual administrative activity.

azure:policy UpdatePolicy m365:unified Set-ADUser OR Set-ADAccountControl
[PolicyBaseline] Expected authentication-related policy configurations to compare against.
AN0291 Analytic 0291
IaaS

Detects unauthorized changes to IAM authentication configurations such as disabling MFA, creating backdoor access keys, or altering trust policies. Correlates identity policy updates with unusual login behavior.

AWS:CloudTrail UpdateLoginProfile AWS:CloudTrail UpdateAccountPasswordPolicy
[ApprovedAccounts] Baseline list of service accounts expected to modify IAM authentication policies.

Detected Techniques

1

Details

MITRE ID
DET0104
STIX ID
x-mitre-detection-strategy--d51dd574-9171-4c46-89bc-0e3bb1178dfe
Analytics
5
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.