Threadlinqs IntelligenceStart free

ATT&CK techniquePersistenceDefense ImpairmentCredential Access

T1556 Modify Authentication Process

PersistenceDefense ImpairmentCredential AccessEnterprise

As of 2026-10-05, T1556 (Modify Authentication Process) appears in 147 tracked threats, first reported 2024-12-16 and most recently 2026-09-30, with linked actors including ShinyHunters, Scattered LAPSUS$ Hunters, The Com; it most often appears alongside T1078 (Valid Accounts).

Tracked threats
14776 critical, 62 high, 7 medium, 1 low
First seen
2024-12-16
Last seen
2026-09-30
Threat actors
60In the threats using it
Detection rules
179Blue tier and above

Data as of:

Activity timeline

T1556 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 52 reports, and 146 of the 147 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1556 Modify Authentication Process is catalogued by MITRE ATT&CK under the Persistence and Defense Impairment and Credential Access tactics in the Enterprise matrix. Threadlinqs maps 147 of 2623 tracked threats (5.6%) to it; by severity that is 76 critical, 62 high, 7 medium, 1 low.

Threats that use T1556 most often also use T1078 Valid Accounts (86 threats), T1190 Exploit Public-Facing Application (86 threats), T1059 Command and Scripting Interpreter (69 threats), T1098 Account Manipulation (61 threats), T1685 Disable or Modify Tools (57 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

60 tracked threat actors appear in the threats that use T1556; the most frequent are ShinyHunters (7), Scattered LAPSUS$ Hunters (6), The Com (5), Scattered Spider (4), UNC6040 (4).

Mitigations

MITRE ATT&CK lists 9 mitigations for T1556.

Data sources

Telemetry that can reveal T1556, per MITRE ATT&CK.

  • Active Directory — Active Directory Object Modification
  • Application Log — Application Log Content
  • Cloud Service — Cloud Service Modification
  • File — File Creation, File Modification
  • Logon Session — Logon Session Creation
  • Module — Module Load
  • Process — OS API Execution, Process Access
  • User Account — User Account Authentication, User Account Modification
  • Windows Registry — Windows Registry Key Creation, Windows Registry Key Modification

Threat actors using it

Tracked threats

The 30 most recent of 147 tracked threats that use T1556.

Detection coverage

Threadlinqs maintains 179 detection rules mapped to T1556 (SPL 56, KQL 65, Sigma 58). Rule content is available to Blue tier accounts and above; this page shows counts only.

179 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques

  • T1556.001 Domain Controller Authentication — 0 tracked threats
  • T1556.002 Password Filter DLL — 0 tracked threats
  • T1556.003 Pluggable Authentication Modules — 9 tracked threats
  • T1556.004 Network Device Authentication — 0 tracked threats
  • T1556.005 Reversible Encryption — 0 tracked threats
  • T1556.006 Multi-Factor Authentication — 22 tracked threats
  • T1556.007 Hybrid Identity — 0 tracked threats
  • T1556.008 Network Provider DLL — 0 tracked threats
  • T1556.009 Conditional Access Policies — 2 tracked threats