Use Alternate Authentication Material

T1550

Technique with 4 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal system access controls.

Authentication processes generally require a valid identity (e.g., username) along with one or more authentication factors (e.g., password, pin, physical smart card, token generator, etc.). Alternate authentication material is legitimately generated by systems after a user or application successfully authenticates by providing a valid identity and the required authentication factor(s). Alternate authentication material may also be generated during the identity creation process.

Caching alternate authentication material allows the system to verify an identity has successfully authenticated without asking the user to reenter authentication factor(s). Because the alternate authentication must be maintained by the system—either in memory or on disk—it may be at risk of being stolen through Credential Access techniques. By stealing alternate authentication material, adversaries are able to bypass system access controls and authenticate to systems without knowing the plaintext password or any additional authentication factors.

Detection rules26

Rules on DetectionCode tagged with T1550 or one of its sub-techniques.

Sigma14

Splunk12

RuleTypeRiskData sourceTechnique
AWS Bedrock Invoke Model Access DeniedTTPNULLAWS CloudTrailT1550
aws detect sts get session token abuseHuntingNULLT1550
Detect Activity Related to Pass the Hash AttacksHuntingNULLWindows Event Log Security 4624T1550.002
Kerberos TGT Request Using RC4 EncryptionTTPNULLWindows Event Log Security 4768T1550
Mimikatz PassTheTicket CommandLine ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1550.003
Okta Multiple Failed Requests to Access ApplicationsHuntingNULLOktaT1550.004
Rubeus Command Line ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1550.003
Rubeus Kerberos Ticket Exports Through Winlogon AccessTTPNULLSysmon EventID 10T1550.003
Unknown Process Using The Kerberos ProtocolTTPNULLSysmon EventID 1 AND Sysmon EventID 3T1550
Windows AD Suspicious Attribute ModificationTTPNULLWindows Event Log Security 5136T1550
Windows Process With NetExec Command Line ParametersTTPNULLWindows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2T1550.003
Windows Steal Authentication Certificates - ESC1 AuthenticationTTPNULLWindows Event Log Security 4887, Windows Event Log Security 4768T1550

Sub-techniques4

IDNameExamples
T1550.001Application Access Token11
T1550.002Pass the Hash22
T1550.003Pass the Ticket6
T1550.004Web Session Cookie2

Groups0

None recorded.

Software1

Campaigns1

Procedure examples2

Software1

Used byProcedure example
MalwareFoggyWeb

FoggyWeb can allow abuse of a compromised AD FS server's SAML token.

Campaigns1

Used byProcedure example
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used forged SAML tokens that allowed the actors to impersonate users and bypass MFA, enabling APT29 to access enterprise cloud applications and services.

References2

  1. NIST Authentication Open source
    NIST. (n.d.). Authentication. Retrieved January 30, 2020.
  2. NIST MFA Open source
    NIST. (n.d.). Multi-Factor Authentication (MFA). Retrieved September 25, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.