{"description": "Enterprise techniques used by Multi-factor Authentication, ATT&CK mitigation M1032 v1.0", "name": "Multi-factor Authentication (M1032)", "domain": "enterprise-attack", "versions": {"layer": "4.3", "attack": "10", "navigator": "4.5"}, "techniques": [{"score": 1, "techniqueID": "T1098", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts."}, {"score": 1, "techniqueID": "T1098.001", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts. Consider enforcing multi-factor authentication for the CreateKeyPair and ImportKeyPair API calls through IAM policies.(Citation: Expel IO Evil in AWS)"}, {"score": 1, "techniqueID": "T1098.002", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts."}, {"score": 1, "techniqueID": "T1098.003", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts."}, {"score": 1, "techniqueID": "T1110", "showSubtechniques": true, "comment": "Use multi-factor authentication. Where possible, also enable multi-factor authentication on externally facing services."}, {"score": 1, "techniqueID": "T1110.001", "showSubtechniques": true, "comment": "Use multi-factor authentication. Where possible, also enable multi-factor authentication on externally facing services."}, {"score": 1, "techniqueID": "T1110.002", "showSubtechniques": true, "comment": "Use multi-factor authentication. Where possible, also enable multi-factor authentication on externally facing services."}, {"score": 1, "techniqueID": "T1110.003", "showSubtechniques": true, "comment": "Use multi-factor authentication. Where possible, also enable multi-factor authentication on externally facing services."}, {"score": 1, "techniqueID": "T1110.004", "showSubtechniques": true, "comment": "Use multi-factor authentication. Where possible, also enable multi-factor authentication on externally facing services."}, {"score": 1, "techniqueID": "T1136", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts."}, {"score": 1, "techniqueID": "T1136.001", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts."}, {"score": 1, "techniqueID": "T1136.002", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts."}, {"score": 1, "techniqueID": "T1136.003", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts."}, {"score": 1, "techniqueID": "T1530", "showSubtechniques": false, "comment": "Consider using multi-factor authentication to restrict access to resources and cloud storage APIs.(Citation: Amazon S3 Security, 2019)"}, {"techniqueID": "T1213", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1213.003", "showSubtechniques": true, "comment": "Use multi-factor authentication for logons to code repositories."}, {"score": 1, "techniqueID": "T1114", "showSubtechniques": true, "comment": "Use of multi-factor authentication for public-facing webmail servers is a recommended best practice to minimize the usefulness of usernames and passwords to adversaries."}, {"score": 1, "techniqueID": "T1114.002", "showSubtechniques": true, "comment": "Use of multi-factor authentication for public-facing webmail servers is a recommended best practice to minimize the usefulness of usernames and passwords to adversaries."}, {"score": 1, "techniqueID": "T1133", "showSubtechniques": false, "comment": "Use strong two-factor or multi-factor authentication for remote service accounts to mitigate an adversary's ability to leverage stolen credentials, but be aware of [Two-Factor Authentication Interception](https://attack.mitre.org/techniques/T1111) techniques for some two-factor authentication implementations."}, {"score": 1, "techniqueID": "T1556", "showSubtechniques": true, "comment": "Integrating multi-factor authentication (MFA) as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access, lateral movement, and collecting information. MFA can also be used to restrict access to cloud resources and APIs. "}, {"score": 1, "techniqueID": "T1556.001", "showSubtechniques": true, "comment": "Integrating multi-factor authentication (MFA) as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access, lateral movement, and collecting information. MFA can also be used to restrict access to cloud resources and APIs. "}, {"score": 1, "techniqueID": "T1556.003", "showSubtechniques": true, "comment": "Integrating multi-factor authentication (MFA) as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access, lateral movement, and collecting information."}, {"score": 1, "techniqueID": "T1556.004", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts. Most embedded network devices support TACACS+ and/or RADIUS.  Follow vendor prescribed best practices for hardening access control. (Citation: Cisco IOS Software Integrity Assurance - TACACS)"}, {"score": 1, "techniqueID": "T1601", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts. Most embedded network devices support TACACS+ and/or RADIUS.  Follow vendor prescribed best practices for hardening access control.(Citation: Cisco IOS Software Integrity Assurance - TACACS)"}, {"score": 1, "techniqueID": "T1601.001", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts. Most embedded network devices support TACACS+ and/or RADIUS.  Follow vendor prescribed best practices for hardening access control.(Citation: Cisco IOS Software Integrity Assurance - TACACS)"}, {"score": 1, "techniqueID": "T1601.002", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts. Most embedded network devices support TACACS+ and/or RADIUS.  Follow vendor prescribed best practices for hardening access control.(Citation: Cisco IOS Software Integrity Assurance - TACACS)"}, {"score": 1, "techniqueID": "T1599", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts. Most embedded network devices support TACACS+ and/or RADIUS.  Follow vendor prescribed best practices for hardening access control.(Citation: Cisco IOS Software Integrity Assurance - TACACS)"}, {"score": 1, "techniqueID": "T1599.001", "showSubtechniques": true, "comment": "Use multi-factor authentication for user and privileged accounts. Most embedded network devices support TACACS+ and/or RADIUS.  Follow vendor prescribed best practices for hardening access control. (Citation: Cisco IOS Software Integrity Assurance - TACACS)"}, {"score": 1, "techniqueID": "T1040", "showSubtechniques": false, "comment": "Use multi-factor authentication wherever possible."}, {"score": 1, "techniqueID": "T1021", "showSubtechniques": true, "comment": "Use multi-factor authentication on remote service logons where possible."}, {"score": 1, "techniqueID": "T1021.001", "showSubtechniques": true, "comment": "Use multi-factor authentication for remote logins.(Citation: Berkley Secure)"}, {"score": 1, "techniqueID": "T1021.004", "showSubtechniques": true, "comment": "Require multi-factor authentication for SSH connections wherever possible, such as password protected SSH keys."}, {"score": 1, "techniqueID": "T1072", "showSubtechniques": false, "comment": "Ensure proper system and access isolation for critical network systems through use of multi-factor authentication."}, {"score": 1, "techniqueID": "T1539", "showSubtechniques": false, "comment": "A physical second factor key that uses the target login domain as part of the negotiation protocol will prevent session cookie theft through proxy methods.(Citation: Evilginx 2 July 2018)"}, {"techniqueID": "T1078", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1078.002", "showSubtechniques": true, "comment": "Integrating multi-factor authentication (MFA) as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access, lateral movement, and collecting information. MFA can also be used to restrict access to cloud resources and APIs."}, {"score": 1, "techniqueID": "T1078.004", "showSubtechniques": true, "comment": "Use multi-factor authentication for cloud accounts, especially privileged accounts. This can be implemented in a variety of forms (e.g. hardware, virtual, SMS), and can also be audited using administrative reporting features.(Citation: AWS - IAM Console Best Practices)"}], "gradient": {"colors": ["#ffffff", "#66b1ff"], "minValue": 0, "maxValue": 1}, "legendItems": [{"label": "used by Multi-factor Authentication", "color": "#66b1ff"}]}