LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1556: Modify Authentication Process

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Adversaries may maliciously modify a part of this process to either reveal credentials or bypass authentication mechanisms. Compromised credentials or access may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access and remote desktop.

EnterpriseT1556TechniqueObject v3.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Modify Authentication Process matters because it targets the trust layer that decides who is allowed in. If an adversary can alter authentication components, they may capture credentials, bypass normal login controls, or preserve access without relying on ordinary valid account use. For leaders, this is an identity resilience issue across Windows, Linux, macOS, network devices, SaaS, IaaS, office suites, and identity providers—not just an endpoint hardening concern.

Executive priority

Prioritize this technique where authentication systems are business-critical: domain controllers, identity providers, VPN or remote access paths, cloud identity integrations, network devices, and externally reachable services. The key executive question is whether the organization can prove authentication mechanisms are hardened, monitored for unauthorized change, and recoverable during an incident. This also supports audit and compliance evidence because mitigations include account management, privileged account management, MFA, permission restriction, OS configuration, and auditing.

Technical view

ATT&CK maps T1556 to defense impairment, persistence, and credential access. SOC, detection engineering, and IR teams should validate monitoring for unauthorized changes to authentication components across the supported platforms. Relationship context shows sub-techniques for Windows domain controller authentication, password filter DLLs, network provider DLLs, reversible encryption, Linux/macOS PAM, network device authentication, MFA modification, hybrid identity, and conditional access policy modification. Because official detection text is not provided, teams should use DET0104, Detect Modification of Authentication Processes Across Platforms, as the ATT&CK-linked detection strategy and test coverage against local authentication architectures.

Likely telemetry

  • Windows security and system events related to authentication configuration, privileged process changes, registry changes, password filter DLLs, network provider DLLs, LSASS/SAM-adjacent activity, and domain controller configuration changes
  • Linux and macOS file integrity, package/configuration, and authentication logs covering PAM files, shared libraries, authorization plugins, and SSH-related authentication components
  • Identity provider, IaaS, SaaS, and office suite audit logs for MFA settings, conditional access policy changes, hybrid identity configuration changes, and privileged identity administration
  • Network device configuration, firmware or system image integrity evidence, authentication configuration changes, and administrative access logs
  • Privileged account activity logs showing who changed authentication controls, when, from where, and through which administrative path

Detection direction

  • Confirm that changes to authentication mechanisms generate alertable events, not just audit records retained for later review.
  • Tune detections around high-risk change points: domain controllers, identity providers, hybrid identity synchronization paths, MFA and conditional access controls, PAM configuration, authentication DLL registration, and network device authentication images or settings.
  • Correlate authentication-process changes with privileged account activity, new persistence indicators, unusual remote access success, and credential-access alerts.
  • Account for legitimate administrative maintenance, OS upgrades, identity policy changes, and network device patching as common false-positive sources; require change-ticket or approved-administrator context where available.
  • Treat absence of official ATT&CK detection text as a coverage gap to validate through local engineering and ATT&CK detection strategy DET0104 rather than assuming tool coverage.

Mitigation priorities

  • Start with auditing: maintain evidence of authentication configuration baselines and review changes on all critical systems and identity platforms.
  • Restrict file, directory, and registry permissions around authentication components so only authorized administrative paths can modify them.
  • Strengthen privileged account and user account management with least privilege, lifecycle controls, and accountability for administrative changes.
  • Apply privileged process integrity and operating system configuration hardening where supported to reduce tampering with authentication-related processes and services.
  • Use MFA and strong password policies, while also monitoring for changes to MFA, reversible encryption, and conditional access controls because this technique can target those defenses directly.
Additional notes and limits

The relationship set broadens the practical scope from host authentication to identity-provider and cloud-connected authentication controls. ATT&CK also relates this technique to ArcaneDoor, FIN13, Ebury, Kessel, and SILENTTRINITY, indicating that multiple campaign, group, and software entries have used or are mapped to this behavior; this should inform threat-informed validation without implying current exposure in any specific environment.

Official detection text for T1556 is not provided. The supplied data identifies platforms, tactics, mitigations, a detection strategy relationship, and sub-technique context, but local architecture determines which authentication components exist and which telemetry is available. This take does not assert active exploitation, customer impact, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Modify Authentication Process

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Adversaries may maliciously modify a part of this process to either reveal credentials or bypass authentication mechanisms. Compromised credentials or access may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access and remote desktop.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

9 rows
DomainIDNameRelationship / procedure
EnterpriseT1556.004Network Device AuthenticationSub-techniqueNetwork Device Authentication subtechnique of this object.
EnterpriseT1556.001Domain Controller AuthenticationSub-techniqueDomain Controller Authentication subtechnique of this object.
EnterpriseT1556.009Conditional Access PoliciesSub-techniqueConditional Access Policies subtechnique of this object.
EnterpriseT1556.008Network Provider DLLSub-techniqueNetwork Provider DLL subtechnique of this object.
EnterpriseT1556.002Password Filter DLLSub-techniquePassword Filter DLL subtechnique of this object.
EnterpriseT1556.006Multi-Factor AuthenticationSub-techniqueMulti-Factor Authentication subtechnique of this object.
EnterpriseT1556.007Hybrid IdentitySub-techniqueHybrid Identity subtechnique of this object.
EnterpriseT1556.005Reversible EncryptionSub-techniqueReversible Encryption subtechnique of this object.
EnterpriseT1556.003Pluggable Authentication ModulesSub-techniquePluggable Authentication Modules subtechnique of this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G1016: FIN13

FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.[1][2]

MalwareEnterprise

S0377: Ebury

Ebury is an OpenSSH backdoor and credential stealer targeting Linux servers and container hosts developed by Windigo. Ebury is primarily installed through modifying shared libraries (`.so` files) executed by the legitimate OpenSSH program. First seen in 2009, Ebury has been used to maintain a botnet of servers, deploy additional malware, and steal cryptocurrency wallets, credentials, and credit card details.[1][2][3][4]

Linux
ToolEnterprise

S0692: SILENTTRINITY

SILENTTRINITY is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers written in Powershell, C, and Boo. SILENTTRINITY was used in a 2019 campaign against Croatian government agencies by unidentified cyber actors.[1][2]

Windows
MalwareEnterprise

S0487: Kessel

Kessel is an advanced version of OpenSSH which acts as a custom backdoor, mainly acting to steal credentials and function as a bot. Kessel has been active since its C2 domain began resolving in August 2018.[1]

Linux
MalwareEnterprise

S9013: DRYHOOK

DRYHOOK is Python script used to steal credentials. DRYHOOK was first reported in January 2025, and has previously been leveraged by People's Republic of China (PRC) state-affiliated threat actors identified as UNC5221 and SYLVANITE.[1][2][3]

LinuxNetwork Devices
CampaignEnterprise

C0046: ArcaneDoor

ArcaneDoor is a campaign targeting networking devices from Cisco and other vendors between July 2023 and April 2024, primarily focused on government and critical infrastructure networks. ArcaneDoor is associated with the deployment of the custom backdoors Line Runner and Line Dancer. ArcaneDoor is attributed to a group referred to as UAT4356 or STORM-1849, and is assessed to be a state-sponsored campaign.[1][2]

Relationship explorer

All related ATT&CK context

subtechnique of · TechniqueT1556.004: Network Device AuthenticationEnterprisesubtechnique of · TechniqueT1556.001: Domain Controller AuthenticationEnterprisemitigates · MitigationM1024: Restrict Registry PermissionsEnterprisemitigates · MitigationM1032: Multi-factor AuthenticationEnterprisesubtechnique of · TechniqueT1556.009: Conditional Access PoliciesEnterprisesubtechnique of · TechniqueT1556.008: Network Provider DLLEnterprisesubtechnique of · TechniqueT1556.002: Password Filter DLLEnterpriseuses · MalwareS0377: EburyEnterprisemitigates · MitigationM1027: Password PoliciesEnterpriseuses · ToolS0692: SILENTTRINITYEnterpriseuses · MalwareS0487: KesselEnterpriseuses · CampaignC0046: ArcaneDoorEnterprisemitigates · MitigationM1022: Restrict File and Directory PermissionsEnterprisesubtechnique of · TechniqueT1556.006: Multi-Factor AuthenticationEnterprisesubtechnique of · TechniqueT1556.007: Hybrid IdentityEnterpriseuses · MalwareS9013: DRYHOOKEnterprisesubtechnique of · TechniqueT1556.005: Reversible EncryptionEnterprisedetects · Detection StrategyDET0104: Detect Modification of Authentication Processes Across PlatformsEnterprisemitigates · MitigationM1018: User Account ManagementEnterprisemitigates · MitigationM1026: Privileged Account ManagementEnterpriseuses · GroupG1016: FIN13Enterprisesubtechnique of · TechniqueT1556.003: Pluggable Authentication ModulesEnterprisemitigates · MitigationM1025: Privileged Process IntegrityEnterprisemitigates · MitigationM1047: AuditEnterprise
Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.0
Created
Modified
Raw hash
cebad3044733d46f...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.13.0Current bundlecebad3044733…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    ESET Ebury Feb 2014

    M.Léveillé, M.. (2014, February 21). An In-depth Analysis of Linux/Ebury. Retrieved April 19, 2019.

    Open source URL
  2. [2]
    store_pwd_rev_enc

    Microsoft. (2021, October 28). Store passwords using reversible encryption. Retrieved January 3, 2022.

    Open source URL
  3. [3]
    GitHub SILENTTRINITY Modules July 2019

    Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022.

    Open source URL
  4. [4]
    ESET ForSSHe December 2018

    Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.

    Open source URL
  5. [5]
    Cisco ArcaneDoor 2024

    Cisco Talos. (2024, April 24). ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices. Retrieved January 6, 2025.

    Open source URL
  6. [6]
    Google UNC5221 Ivanti January 2025

    John Wolfram, Josh Murchie, Matt Lin, Daniel Ainsworth, Robert Wallace, Dimiter Andonov, Dhanesh Kizhakkinan, Jacob Thompson. (2025, January 8). Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation. Retrieved April 14, 2026.

    Open source URL
  7. [7]
    Picus Security UNC5221 Ivanti May 2025

    Sila Ozeren Hacioglu. (2025, May 5). UNC5221’s Latest Exploit: Weaponizing CVE-2025-22457 in Ivanti Connect Secure. Retrieved April 13, 2026.

    Open source URL
  8. [8]
    TechNet Credential Theft

    Microsoft. (2016, April 15). Attractive Accounts for Credential Theft. Retrieved June 3, 2016.

    Open source URL
  9. [9]
    TechNet Least Privilege

    Microsoft. (2016, April 16). Implementing Least-Privilege Administrative Models. Retrieved June 3, 2016.

    Open source URL
  10. [10]
    Microsoft Securing Privileged Access

    Plett, C., Poggemeyer, L. (12, October 26). Securing Privileged Access Reference Material. Retrieved April 25, 2017.

    Open source URL
  11. [11]
    MagicWeb

    Microsoft Threat Intelligence Center, Microsoft Detection and Response Team, Microsoft 365 Defender Research Team . (2022, August 24). MagicWeb: NOBELIUM’s post-compromise trick to authenticate as anyone. Retrieved September 28, 2022.

    Open source URL
  12. [12]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  13. [13]
    Microsoft LSA

    Microsoft. (2013, July 31). Configuring Additional LSA Protection. Retrieved February 13, 2015.

    Open source URL
  14. [14]
    Mandiant Azure AD Backdoors

    Mike Burns. (2020, September 30). Detecting Microsoft 365 and Azure Active Directory Backdoors. Retrieved September 28, 2022.

    Open source URL
  15. [15]
    EnableMPRNotifications

    Microsoft. (2023, January 26). Policy CSP - WindowsLogon. Retrieved March 30, 2023.

    Open source URL
  16. [16]
    mitre-attackT1556
    Open source URL
  17. [17]
    mitre-attackT1556
    Open source URL
  18. [18]
    mitre-attackT1556
    Open source URL
  19. [19]
    ESET Ebury Feb 2014

    M.Léveillé, M.. (2014, February 21). An In-depth Analysis of Linux/Ebury. Retrieved April 19, 2019.

    Open source URL
  20. [20]
    store_pwd_rev_enc

    Microsoft. (2021, October 28). Store passwords using reversible encryption. Retrieved January 3, 2022.

    Open source URL
  21. [21]
    GitHub SILENTTRINITY Modules July 2019

    Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022.

    Open source URL
  22. [22]
    ESET ForSSHe December 2018

    Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.

    Open source URL
  23. [23]
    Cisco ArcaneDoor 2024

    Cisco Talos. (2024, April 24). ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices. Retrieved January 6, 2025.

    Open source URL
  24. [24]
    Google UNC5221 Ivanti January 2025

    John Wolfram, Josh Murchie, Matt Lin, Daniel Ainsworth, Robert Wallace, Dimiter Andonov, Dhanesh Kizhakkinan, Jacob Thompson. (2025, January 8). Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation. Retrieved April 14, 2026.

    Open source URL
  25. [25]
    Picus Security UNC5221 Ivanti May 2025

    Sila Ozeren Hacioglu. (2025, May 5). UNC5221’s Latest Exploit: Weaponizing CVE-2025-22457 in Ivanti Connect Secure. Retrieved April 13, 2026.

    Open source URL
  26. [26]
    MagicWeb

    Microsoft Threat Intelligence Center, Microsoft Detection and Response Team, Microsoft 365 Defender Research Team . (2022, August 24). MagicWeb: NOBELIUM’s post-compromise trick to authenticate as anyone. Retrieved September 28, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.