Activity timeline
T1556 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 52 reports, and 146 of the 147 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1556 Modify Authentication Process is catalogued by MITRE ATT&CK under the Persistence and Defense Impairment and Credential Access tactics in the Enterprise matrix. Threadlinqs maps 147 of 2623 tracked threats (5.6%) to it; by severity that is 76 critical, 62 high, 7 medium, 1 low.
Threats that use T1556 most often also use T1078 Valid Accounts (86 threats), T1190 Exploit Public-Facing Application (86 threats), T1059 Command and Scripting Interpreter (69 threats), T1098 Account Manipulation (61 threats), T1685 Disable or Modify Tools (57 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
60 tracked threat actors appear in the threats that use T1556; the most frequent are ShinyHunters (7), Scattered LAPSUS$ Hunters (6), The Com (5), Scattered Spider (4), UNC6040 (4).
Mitigations
MITRE ATT&CK lists 9 mitigations for T1556.
Data sources
Telemetry that can reveal T1556, per MITRE ATT&CK.
- Active Directory — Active Directory Object Modification
- Application Log — Application Log Content
- Cloud Service — Cloud Service Modification
- File — File Creation, File Modification
- Logon Session — Logon Session Creation
- Module — Module Load
- Process — OS API Execution, Process Access
- User Account — User Account Authentication, User Account Modification
- Windows Registry — Windows Registry Key Creation, Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 147 tracked threats that use T1556.
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…high
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active Exploitationcritical
- Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account…high
- N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EUhigh
- Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively…critical
- Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi…high
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…high
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)critical
- DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…high
- HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code…critical
- Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth…critical
- CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain…high
- Multiple Zscaler Client Connector Flaws Enable Remote Code Execution (CVE-2026-59568)critical
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…critical
- Metabase Unauthenticated SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) Exploited to Steal…critical
- BdThemes WordPress Plugin Supply-Chain Attack Poisons API to Create Rogue Adminsmedium
- WordPress Supply Chain Attack via BdThemes Promotional API Feed Poisoning (Element Pack, Prime Slider, and 5…high
- AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671…high
- UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for…critical
- FirewallFalcon Manager: Supply-Chain Backdoor in Underground VPN Server Infrastructurecritical
- Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance…high
- Agent-to-Agent Privilege Boundary Failures in Google ADK for Python (adk-python) CI/CD Workflows via…critical
- Apple challenges UK Home Office Technical Capability Notice over encrypted iCloud access (Advanced Data…high
- Pass-ta-key Attacks Enable Malware to Hijack Google-Synced Passkeys via Chrome/TPM/Google Cloud…high
- Google Password Manager — Three Post-Compromise Attack Paths Against Chrome Cloud Authenticator (Pass-ta-key…high
- CVE-2026-17059: Keycloak Admin REST API Broken Object-Level Authorization Exposes User PIImedium
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeyshigh
- PamDOORa: Commercialized PAM-Abuse Backdoor for SSH Credential Theft on Linux — Evolution of the Plague /…high
Detection coverage
Threadlinqs maintains 179 detection rules mapped to T1556 (SPL 56, KQL 65, Sigma 58). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1556.001 Domain Controller Authentication — 0 tracked threats
- T1556.002 Password Filter DLL — 0 tracked threats
- T1556.003 Pluggable Authentication Modules — 9 tracked threats
- T1556.004 Network Device Authentication — 0 tracked threats
- T1556.005 Reversible Encryption — 0 tracked threats
- T1556.006 Multi-Factor Authentication — 22 tracked threats
- T1556.007 Hybrid Identity — 0 tracked threats
- T1556.008 Network Provider DLL — 0 tracked threats
- T1556.009 Conditional Access Policies — 2 tracked threats