Skip to content
← LibraryTechnique entry
T1556Credential Access

Modify Authentication Process

Subvert auth — Skeleton Key, password filter DLLs, fake LDAP listeners, swapping cert / key material, SSO IdP tampering.

§ Where this technique fits

T1556 is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 5 approved dossiers in the registry, typically at step 4.2 on average.

Authoritative reference: attack.mitre.org/techniques/T1556/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Valid Accounts
    T1078 · Initial Access
    seen 2×
  2. 02
    AITM Phishing — Evilginx / Modlishka
    PH-AITM-EVILGINX · Initial Access
    seen 1×
  3. 03
    Password Spraying
    T1110.003 · Credential Access
    seen 1×