Basyrix SOC Response Atlas by Basyrix

Credential Access

T1111 — Multi-Factor Authentication Interception

Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources. Use of MFA is recommended and provides a higher level of security than usernames and passwords alone, but organizations should be aware of techniques that could be used to intercept and bypass these security mechanisms...

Investigate Multi-Factor Authentication Interception activity in the context of Credential Access: confirm scope, affected host/identity, and whether it matches expected administrative behaviour before deciding this is benign.

Platforms

Linux, macOS, Windows

Priority / status

high / draft

Evidence to collect

  • Host or resource affected
  • Account or identity involved
  • Timestamp of the activity
  • Related process, file, or network artifact
  • Any preceding or follow-on alerts