M ManySignal
T1556 MITRE ATT&CK

T1556 Modify Authentication Process — Detection & Response

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSAS) on Windows or Pluggable Authentication Modules (PAM) on Unix-based systems.

Coverage at a glance

Detections shipped
3
Avg. verdict time
< 5 min
Data sources
3+

Threat context

How adversaries use T1556 Modify Authentication Process — Detection & Response

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSAS) on Windows or Pluggable Authentication Modules (PAM) on Unix-based systems.

MFA modification (T1556.006) is an increasingly observed technique where attackers with admin access register their own MFA factors (authenticator apps, phone numbers) to an existing account, establishing persistent access that survives password resets. Hybrid Identity attacks (T1556.007) exploit federated identity configurations — the Golden SAML technique forges SAML assertions using the AD FS token-signing certificate, enabling persistent access to cloud services without authenticating against the on-premises identity provider.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

New MFA Factor Registered for High-Privilege User — Admin account adds new authenticator

A privileged user registers a new MFA factor from an unrecognised device or unusual location.

Critical Okta / Entra ID

SAML Token Signing Certificate Accessed — AD FS certificate private key read

The AD FS token signing certificate private key is accessed, enabling Golden SAML token forgery.

Critical Windows Event Log / CrowdStrike

SAML Provider Modified in AWS — UpdateSAMLProvider API call

The SAML identity provider configuration in AWS IAM is modified, potentially replacing it with an attacker-controlled IdP.

High AWS CloudTrail

T1556 Modify Authentication Process — Detection & Response: frequently asked questions

What is Golden SAML and how does ManySignal detect it?

Golden SAML is an attack where the adversary steals the AD FS token signing certificate and uses it to forge SAML assertions for any user, including admins. ManySignal detects the certificate access event on the AD FS server (via EDR telemetry) and correlates with subsequent anomalous sign-ins to cloud services.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.