# T1556 Modify Authentication Process

> As of 2026-10-05, T1556 (Modify Authentication Process) appears in 147 tracked threats, first reported 2024-12-16 and most recently 2026-09-30, with linked actors including ShinyHunters, Scattered LAPSUS$ Hunters, The Com; it most often appears alongside T1078 (Valid Accounts).

- **Tracked threats:** 147 (76 critical, 62 high, 7 medium, 1 low)
- **First seen:** 2024-12-16
- **Last seen:** 2026-09-30
- **Threat actors:** 60
- **Detection rules:** 179 (counts only; Blue tier and above)

## Key facts

- **ID:** T1556
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Defense Impairment, Credential Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1556/

## Activity timeline

T1556 first appeared in tracked threats on 2024-12-16 and was most recently reported on 2026-09-30. The busiest month was 2026-07 with 52 reports, and 146 of the 147 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1556 Modify Authentication Process is catalogued by MITRE ATT&CK under the Persistence and Defense Impairment and Credential Access tactics in the Enterprise matrix. Threadlinqs maps 147 of 2623 tracked threats (5.6%) to it; by severity that is 76 critical, 62 high, 7 medium, 1 low.

Threats that use T1556 most often also use [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (86 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (86 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (69 threats), [T1098 Account Manipulation](https://intel.threadlinqs.com/technique/T1098) (61 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (57 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

60 tracked threat actors appear in the threats that use T1556; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (7), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (6), [The Com](https://intel.threadlinqs.com/actor/The%20Com) (5), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (4), [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) (4).

## Mitigations

MITRE ATT&CK lists 9 mitigations for T1556.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1024 Restrict Registry Permissions](https://attack.mitre.org/mitigations/M1024/)
- [M1025 Privileged Process Integrity](https://attack.mitre.org/mitigations/M1025/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1556, per MITRE ATT&CK.

- Active Directory — Active Directory Object Modification
- Application Log — Application Log Content
- Cloud Service — Cloud Service Modification
- File — File Creation, File Modification
- Logon Session — Logon Session Creation
- Module — Module Load
- Process — OS API Execution, Process Access
- User Account — User Account Authentication, User Account Modification
- Windows Registry — Windows Registry Key Creation, Windows Registry Key Modification

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 7
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 6
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 5
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 4
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 4
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 4
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 4
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 3
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 3
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 3
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 2

## Tracked threats

The 30 most recent of 147 tracked threats that use T1556.

- [CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…](https://intel.threadlinqs.com/threat/TL-2026-2802) — high — 2026-09-30
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2688) — critical — 2026-09-27
- [Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account…](https://intel.threadlinqs.com/threat/TL-2026-2672) — high — 2026-09-26
- [N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EU](https://intel.threadlinqs.com/threat/TL-2026-2537) — high — 2026-09-16
- [Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively…](https://intel.threadlinqs.com/threat/TL-2026-2486) — critical — 2026-09-13
- [Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi…](https://intel.threadlinqs.com/threat/TL-2026-2446) — high — 2026-09-11
- [Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…](https://intel.threadlinqs.com/threat/TL-2026-2420) — high — 2026-09-09
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)](https://intel.threadlinqs.com/threat/TL-2026-2345) — critical — 2026-09-06
- [DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…](https://intel.threadlinqs.com/threat/TL-2026-2329) — high — 2026-09-04
- [HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code…](https://intel.threadlinqs.com/threat/TL-2026-2314) — critical — 2026-09-03
- [Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth…](https://intel.threadlinqs.com/threat/TL-2026-2159) — critical — 2026-08-26
- [CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain…](https://intel.threadlinqs.com/threat/TL-2026-2151) — high — 2026-08-26
- [Multiple Zscaler Client Connector Flaws Enable Remote Code Execution (CVE-2026-59568)](https://intel.threadlinqs.com/threat/TL-2026-2139) — critical — 2026-08-25
- [CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…](https://intel.threadlinqs.com/threat/TL-2026-2080) — critical — 2026-08-20
- [Metabase Unauthenticated SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) Exploited to Steal…](https://intel.threadlinqs.com/threat/TL-2026-1980) — critical — 2026-08-10
- [BdThemes WordPress Plugin Supply-Chain Attack Poisons API to Create Rogue Admins](https://intel.threadlinqs.com/threat/TL-2026-1978) — medium — 2026-08-10
- [WordPress Supply Chain Attack via BdThemes Promotional API Feed Poisoning (Element Pack, Prime Slider, and 5…](https://intel.threadlinqs.com/threat/TL-2026-1971) — high — 2026-08-10
- [AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671…](https://intel.threadlinqs.com/threat/TL-2026-1963) — high — 2026-08-09
- [UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for…](https://intel.threadlinqs.com/threat/TL-2026-1959) — critical — 2026-08-09
- [FirewallFalcon Manager: Supply-Chain Backdoor in Underground VPN Server Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-1947) — critical — 2026-08-07
- [Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance…](https://intel.threadlinqs.com/threat/TL-2026-1930) — high — 2026-08-07
- [Agent-to-Agent Privilege Boundary Failures in Google ADK for Python (adk-python) CI/CD Workflows via…](https://intel.threadlinqs.com/threat/TL-2026-1897) — critical — 2026-08-05
- [Apple challenges UK Home Office Technical Capability Notice over encrypted iCloud access (Advanced Data…](https://intel.threadlinqs.com/threat/TL-2026-1868) — high — 2026-08-04
- [Pass-ta-key Attacks Enable Malware to Hijack Google-Synced Passkeys via Chrome/TPM/Google Cloud…](https://intel.threadlinqs.com/threat/TL-2026-1852) — high — 2026-08-03
- [Google Password Manager — Three Post-Compromise Attack Paths Against Chrome Cloud Authenticator (Pass-ta-key…](https://intel.threadlinqs.com/threat/TL-2026-1843) — high — 2026-08-03
- [CVE-2026-17059: Keycloak Admin REST API Broken Object-Level Authorization Exposes User PII](https://intel.threadlinqs.com/threat/TL-2026-1796) — medium — 2026-07-31
- [Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys](https://intel.threadlinqs.com/threat/TL-2026-1793) — high — 2026-07-31
- [PamDOORa: Commercialized PAM-Abuse Backdoor for SSH Credential Theft on Linux — Evolution of the Plague /…](https://intel.threadlinqs.com/threat/TL-2026-1772) — high — 2026-07-30

## Related CVEs

CVEs referenced by the tracked threats that use T1556, most frequent first.

- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-57092](https://intel.threadlinqs.com/cve/CVE-2026-57092)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719)
- [CVE-2026-20182](https://intel.threadlinqs.com/cve/CVE-2026-20182)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-42271](https://intel.threadlinqs.com/cve/CVE-2026-42271)
- [CVE-2026-48558](https://intel.threadlinqs.com/cve/CVE-2026-48558)
- [CVE-2026-48710](https://intel.threadlinqs.com/cve/CVE-2026-48710)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)

## Detection coverage

Threadlinqs maintains 179 detection rules mapped to T1556 (SPL 56, KQL 65, Sigma 58). Rule content is available to Blue tier accounts and above; this page shows counts only.

179 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1556.001 Domain Controller Authentication — 0 tracked threats
- T1556.002 Password Filter DLL — 0 tracked threats
- T1556.003 Pluggable Authentication Modules — 9 tracked threats
- T1556.004 Network Device Authentication — 0 tracked threats
- T1556.005 Reversible Encryption — 0 tracked threats
- [T1556.006 Multi-Factor Authentication](https://intel.threadlinqs.com/technique/T1556.006) — 22 tracked threats
- T1556.007 Hybrid Identity — 0 tracked threats
- T1556.008 Network Provider DLL — 0 tracked threats
- T1556.009 Conditional Access Policies — 2 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1556
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
