Sub-technique of T1556 Modify Authentication Process.View on attack.mitre.org
Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native authentication mechanisms for local accounts on network devices.
Modify System Image may include implanted code to the operating system for network devices to provide access for adversaries using a specific password. The modification includes a specific password which is implanted in the operating system image via the patch. Upon authentication attempts, the inserted code will first check to see if the user input is the password. If so, access is granted. Otherwise, the implanted code will pass the credentials on for verification of potentially valid credentials.
Rules on DetectionCode tagged with T1556.004.
| Rule | Level | Log source |
|---|---|---|
| Cisco Dot1x Disabled | medium | cisco / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco ASA - AAA Policy Tampering | Anomaly | NULL | Cisco ASA Logs |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareDRYHOOK | DRYHOOK has patched victim appliances authentication routines to capture credentials in plaintext as users log in. |
| MalwareSLOWPULSE | SLOWPULSE can modify LDAP and two factor authentication flows by inspecting login credentials and forcing successful authentication if the provided password matches a chosen backdoor password. |
| MalwareSYNful Knock | SYNful Knock has the capability to add its own custom backdoor password when it modifies the operating system of the affected network device. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.