Techniques › T1621
T1621 Multi-Factor Authentication Request Generation
credential access — Windows, Linux, macOS, IaaS, SaaS, Office Suite, Identity Provider · attack.mitre.org · JSON
1
MITRE detection strategy
6
analytics
2
Sigma rules tagged attack.t1621
0
KEV CVEs mapped here
<p>Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.</p><p>Adversaries in possession of credentials to Valid Accounts may be unable to complete the login process if they lack access to the 2FA or MFA mechanisms required as an additional credential and security control. To circumvent this, adversaries may abuse the automatic generation of push notifications to MFA services such as Duo Push, Microsoft Authenticator, Okta, or similar services to have the user grant access to their account. If adversaries lack credentials to victim accounts, they may also abuse automatic push notification generation when this option is configured for self-service password reset (SSPR).</p><p>In some cases, adversaries may continuously repeat login attempts in order to bombard users with MFA push notifications, SMS messages, and phone calls, potentially resulting in the user finally accepting the authentication request in response to “MFA fatigue.”</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0160 Detection Strategy for Multi-Factor Authentication Request Generation (T1621) v1.0
AN0449 Identity ProviderMonitor for excessive or anomalous MFA push notifications or token requests, especially when login attempts originate from unusual IPs or geolocations and do not correspond to legitimate user-initiated sessions.azure:signinlogs
Multiple MFA challenge requests without successful primary login→ DC0002 User Account AuthenticationTunable:TimeWindowGeoIPAllowListAN0450 IaaSDetect abnormal MFA activity within cloud service provider logs, such as repeated generation of MFA challenges for the same user session or mismatched MFA device and login origin.AWS:CloudTrailAssumeRole or ConsoleLogin with repeated MFA failures followed by repeated MFA requests→ DC0002 User Account AuthenticationTunable:FailedLoginThresholdAN0451 WindowsDetect repeated failed login events followed by MFA challenges triggered in rapid succession, especially if originating from service accounts or anomalous IP addresses.Tunable:ServiceAccountExclusionAN0452 LinuxMonitor PAM and syslog entries for unusual frequency of login attempts that trigger MFA prompts, particularly when MFA challenges do not match expected user behavior.auditd:AUTHpam_unix or pam_google_authenticator invoked repeatedly within short interval→ DC0002 User Account AuthenticationTunable:AuthRetryThresholdAN0453 SaaSDetect anomalous OAuth or SSO logins that repeatedly generate MFA challenges, particularly where MFA approvals are denied or timed out by the user.Tunable:MFAProviderAN0454 macOSDetect user account logon attempts that trigger multiple MFA challenges through enterprise identity integrations, especially if MFA push requests are generated without successful interactive login.Tunable:DeviceEnrollmentStatus
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1621
Author: AlertIQ
· 2021-10-10 (modified 2022-12-18) · logsource: product=azure service=signinlogs · 5496ff55-42ec-4369-81cb-00f417029e25
Identifies user login with multifactor authentication failures, which might be an indication an attacker has the password for the account but can't pass the MFA challenge.
Author: AlertIQ
· 2022-03-24 · logsource: product=azure service=signinlogs · e40f4962-b02b-4192-9bfe-245f7ece1f99
User has indicated they haven't instigated the MFA prompt and could indicate an attacker has the password for the account.