Basyrix SOC Response Atlas by Basyrix

Defense Impairment · Persistence · Credential Access

T1556 — Modify Authentication Process

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials...

Investigate Modify Authentication Process activity in the context of Defense Impairment/Persistence/Credential Access: confirm scope, affected host/identity, and whether it matches expected administrative behaviour before deciding this is benign.

Platforms

IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows

Priority / status

high / draft

Evidence to collect

  • Host or resource affected
  • Account or identity involved
  • Timestamp of the activity
  • Related process, file, or network artifact
  • Any preceding or follow-on alerts