{"data":{"id":"IA-02","name":"Identification and Authentication (Organizational Users)","family":"IA","family_name":"Identification and Authentication","withdrawn":false,"description":"Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.","supplemental_guidance":"Organizations can satisfy the identification and authentication requirements by complying with the requirements in [HSPD 12]. Organizational users include employees or individuals who organizations consider to have an equivalent status to employees (e.g., contractors and guest researchers). Unique identification and authentication of users applies to all accesses other than those that are explicitly identified in AC-14 and that occur through the authorized use of group authenticators without individual authentication. Since processes execute on behalf of groups and roles, organizations may require unique identification of individuals in group accounts or for detailed accountability of individual activity.\n\nOrganizations employ passwords, physical authenticators, or biometrics to authenticate user identities or, in the case of multi-factor authentication, some combination thereof. Access to organizational systems is defined as either local access or network access. Local access is any access to organizational systems by users or processes acting on behalf of users, where access is obtained through direct connections without the use of networks. Network access is access to organizational systems by users (or processes acting on behalf of users) where access is obtained through network connections (i.e., nonlocal accesses). Remote access is a type of network access that involves communication through external networks. Internal networks include local area networks and wide area networks.\n\nThe use of encrypted virtual private networks for network connections between organization-controlled endpoints and non-organization-controlled endpoints may be treated as internal networks with respect to protecting the confidentiality and integrity of information traversing the network. Identification and authentication requirements for non-organizational users are described in IA-8.","enhancements":[{"id":"IA-02(01)","name":"Multi-factor Authentication to Privileged Accounts","statement":"Implement multi-factor authentication for access to privileged accounts.","baselines":["low","moderate","high"]},{"id":"IA-02(02)","name":"Multi-factor Authentication to Non-privileged Accounts","statement":"Implement multi-factor authentication for access to non-privileged accounts.","baselines":["low","moderate","high"]},{"id":"IA-02(03)","name":"Local Access to Privileged Accounts","withdrawn":true,"incorporated_into":["IA-02(01)"]},{"id":"IA-02(04)","name":"Local Access to Non-privileged Accounts","withdrawn":true,"incorporated_into":["IA-02(02)"]},{"id":"IA-02(05)","name":"Individual Authentication with Group Authentication","statement":"When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources.","baselines":["high"]},{"id":"IA-02(06)","name":"Access to Accounts —separate Device","statement":"Implement multi-factor authentication for [Selection (one or more): local; network; remote] access to [Selection (one or more): privileged accounts; non-privileged accounts] such that:\na. One of the factors is provided by a device separate from the system gaining access; and\nb. The device meets [Assignment: organization-defined strength of mechanism requirements].","baselines":[]},{"id":"IA-02(07)","name":"Network Access to Non-privileged Accounts — Separate Device","withdrawn":true,"incorporated_into":["IA-02(06)"]},{"id":"IA-02(08)","name":"Access to Accounts — Replay Resistant","statement":"Implement replay-resistant authentication mechanisms for access to [Selection (one or more): privileged accounts; non-privileged accounts].","baselines":["low","moderate","high"]},{"id":"IA-02(09)","name":"Network Access to Non-privileged Accounts — Replay Resistant","withdrawn":true,"incorporated_into":["IA-02(08)"]},{"id":"IA-02(10)","name":"Single Sign-on","statement":"Provide a single sign-on capability for [Assignment: organization-defined system accounts and services].","baselines":[]},{"id":"IA-02(11)","name":"Remote Access — Separate Device","withdrawn":true,"incorporated_into":["IA-02(06)"]},{"id":"IA-02(12)","name":"Acceptance of PIV Credentials","statement":"Accept and electronically verify Personal Identity Verification-compliant credentials.","baselines":["low","moderate","high"]},{"id":"IA-02(13)","name":"Out-of-band Authentication","statement":"Implement the following out-of-band authentication mechanisms under [Assignment: organization-defined conditions]: [Assignment: organization-defined out-of-band authentication].","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"IA-02","name":"Identification and Authentication (Organizational Users)","description":"Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.","discussion":"Organizations can satisfy the identification and authentication requirements by complying with the requirements in [HSPD 12]. Organizational users include employees or individuals who organizations consider to have an equivalent status to employees (e.g., contractors and guest researchers). Unique identification and authentication of users applies to all accesses other than those that are explicitly identified in AC-14 and that occur through the authorized use of group authenticators without individual authentication. Since processes execute on behalf of groups and roles, organizations may require unique identification of individuals in group accounts or for detailed accountability of individual activity.\n\nOrganizations employ passwords, physical authenticators, or biometrics to authenticate user identities or, in the case of multi-factor authentication, some combination thereof. Access to organizational systems is defined as either local access or network access. Local access is any access to organizational systems by users or processes acting on behalf of users, where access is obtained through direct connections without the use of networks. Network access is access to organizational systems by users (or processes acting on behalf of users) where access is obtained through network connections (i.e., nonlocal accesses). Remote access is a type of network access that involves communication through external networks. Internal networks include local area networks and wide area networks.\n\nThe use of encrypted virtual private networks for network connections between organization-controlled endpoints and non-organization-controlled endpoints may be treated as internal networks with respect to protecting the confidentiality and integrity of information traversing the network. Identification and authentication requirements for non-organizational users are described in IA-8.","related_controls":["AC-02","AC-03","AC-04","AC-14","AC-17","AC-18","AU-01","AU-06","IA-04","IA-05","IA-08","IA-13","MA-04","MA-05","PE-02","PL-04","SA-04","SA-08"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.5.16","A.8.5"],"iso_27002_2022":["5.16","8.5"],"cobit_2019":["DSS05"],"pci_dss_v4":["8.1","8.3","8.4","8.5"],"nist_csf_2":["PR.AA-01","PR.AA-03","PR.AA-04"],"cis_controls_v8":["CIS 5","CIS 5.6","CIS 6.3","CIS 6.4","CIS 6.5","CIS 12.5","CIS 12.7"],"soc2_tsc":["CC6.1","CC6.1-POF3","CC6.1-POF4","CC6.1-POF8"],"finos_ccc":["CCC-C03","CCC-C11"],"iso_42001_2023":[],"iec_62443":["3-3 SR 1.1"],"asd_e8":["E8-7","E8-7 ML1","E8-7 ML2","E8-7 ML3"],"nis2":["Art. 21(2)(j)"],"apra_cps_234":[],"mas_trm":["9","14"],"pra_op_resilience":[],"bsi_grundschutz":["ORP.4"],"anssi":["Hygiene.10","Hygiene.11","Hygiene.12","RGS.2.2","SecNumCloud.10.5"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.B.d(60)","IV.C(61)"],"gdpr":["Art.32(1)(b)","Art.32(1)(d)"],"dora":["Art.9(4)(c)","Art.9(4)(d)"],"bio2":["5.16","8.5"],"rbi_csf":["Annex1.8","Annex1.9","ITGRCA.19"],"fisc":["FISC.T2","FISC.T10","FISC.T11"],"lgpd_bcb":["BCB.Art.3","BCB.OpenFinance","BCB.PIX","LGPD.Art.46"],"hkma_tme1":["TME1.8.2","TME1.8.3","TME1.8.5","TME1.10.2","TME1.10.4"],"mlps_2":["8.1.4.1","8.2"],"dnb_good_practice":["DNB.17.1"],"cra":["CRA.I.2d"],"swift_cscf":["SWIFT.1.2","SWIFT.4.2"],"cbb_tm":["TM-6"],"cbuae":["CR-4"],"nca_ecc":["2-2","5-1"],"qatar_nia":["AC"],"sama_csf":["3.1"],"uae_ia":["T9"],"bog_cisd":["CISD-IX","CISD-VIII"],"bom_ctrm":["3.3","3.13"],"cbe_csf":["CTO-1","CTO-5"],"cbn_csf":["Part3.2","Part5.2"],"popia":["s19"],"sa_js2":["JS2-7.1","JS2-8.1"],"bot_cyber":["Ch2.2","Ch8.2","Ch9.1"],"cpmi_pfmi":["CG.PR","PFMI.P17"],"eba_ict":["3.4.2","3.8(b)"],"ecb_croe":["CROE.2.3.1"],"ffiec_is":["II.C.7(b)","II.C.15","II.C.15(a)","II.C.15(b)","II.C.15(c)","II.C.16"],"hipaa_sr":["§164.310(a)(2)(iii)","§164.312(a)(2)(i)","§164.312(d)"],"iosco_cyber":["PROT-1"],"nydfs_500":["500.7","500.12"],"sebi_cscrf":["PR.AA"],"cmmc_2":["AC","IA"],"nerc_cip":["CIP-005-7"],"nrc_73_54":["RG5.71-A-AC"],"tsa_psd":["SD-2 Sec B"],"ieee_1686":["5.1"],"ferc_cip":["Order 850"],"doe_c2m2":["ACCESS"],"api_1164":["Sec 6"],"awia":["AWWA Sec 3"],"iaea_nss":["Sec 5.2"],"pci_pts":["C"],"fips_140":["FIPS 140-3 §7.4"],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FIA"],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.3"],"fda_21_cfr_11":["§11.10(d)","§11.100(a)","§11.200(a)(1)","§11.200(a)(1)(ii)","§11.200(a)(2)","§11.200(a)(3)"],"fda_cyber":["SA-1"],"hitrust_csf":["01.a","01.c"],"iso_27799":["9.3","9.4","H.5"],"lloyds_ms":["MS8.3"],"naic_ds":["4-access","4B"],"nhs_dspt":["NDG-4.1","NDG-4.3"],"pra_ss1_23":["P-IT.1"],"solvency_ii":["EIOPA-ICT-4.4"],"owasp_masvs_v2":["MASVS-AUTH-1","MASVS-AUTH-2","MASVS-AUTH-3"],"csa_ccm_v4":["IAM-10","IAM-13","IAM-14","IAM-15"],"csa_aicm":["IAM-10","IAM-13","IAM-14","IAM-15","IAM-17"],"ccss_v9":["1.03.5","1.04.1","1.04.3","1.05.1","1.05.3"],"mica":["Art.40(1)","Art.55(1)","Art.63(1)","Art.67(1)","Art.72(1)","Art.76(1)"],"basel_sco60":["SCO60.62","SCO60.66","SCO60.71"],"bssc":["GSP-11","KMS-06","NOS-05"],"sec_custody_digital":["SEC-CD-03","SEC-CD-05","SEC-CD-16"],"dpdpa":["Act.8(5)","Rules.6(1)(b)","Rules.Sch1.B.7"]},"attack_techniques":[{"id":"T1003","name":"OS Credential Dumping","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong user identification and authentication mechanisms, including multi-factor authentication, reduce the value of dumped credential hashes by requiring additional authentication factors beyond passwords alone."},{"id":"T1021","name":"Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Requiring unique identification and robust authentication at remote service endpoints ensures adversaries cannot access RDP, SSH, SMB, or other services without presenting valid, verified credentials."},{"id":"T1040","name":"Network Sniffing","tactics":["credential-access","discovery"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor and token-based authentication mechanisms render credentials captured through network sniffing less useful, as intercepted password hashes or cleartext passwords alone are insufficient for access."},{"id":"T1047","name":"Windows Management Instrumentation","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Requiring authenticated and uniquely identified sessions for WMI operations ensures adversaries cannot execute remote management commands without first proving their identity through approved authentication methods."},{"id":"T1053","name":"Scheduled Task/Job","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"User identification requirements on task scheduling services ensure that scheduled tasks and jobs are attributed to authenticated users, preventing anonymous creation of persistent scheduled execution."},{"id":"T1055","name":"Process Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements at the process and session level ensure that process injection attempts must originate from authenticated user contexts, enabling attribution and restricting injection from anonymous processes."},{"id":"T1059","name":"Command and Scripting Interpreter","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Requiring authentication before granting access to command interpreters ensures adversaries must first establish an authenticated session, preventing anonymous script execution on managed systems."},{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Robust authentication on software deployment tool consoles and APIs ensures only verified administrators can push software packages, preventing adversary exploitation of deployment infrastructure."},{"id":"T1078","name":"Valid Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Strong user identification and multi-factor authentication make it significantly harder for adversaries to exploit valid credentials, as stolen passwords alone are insufficient when additional authentication factors are required."},{"id":"T1098","name":"Account Manipulation","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication controls ensure that account manipulation operations are performed only by properly identified and authenticated administrators, preventing unauthorized modification of account attributes and permissions."},{"id":"T1110","name":"Brute Force","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Implementing strong authentication mechanisms such as MFA, certificate-based authentication, and phishing-resistant protocols makes brute force attacks ineffective even if password guessing succeeds."},{"id":"T1111","name":"Multi-Factor Authentication Interception","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Layered authentication with multiple independent factors, including phishing-resistant options like FIDO2, reduces the effectiveness of MFA interception techniques that target only a single authentication factor."},{"id":"T1114","name":"Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Requiring strong authentication for email access, including modern authentication protocols and MFA, prevents adversaries from accessing mailboxes using stolen legacy credentials or basic authentication."},{"id":"T1133","name":"External Remote Services","tactics":["initial-access","persistence"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication requirements on external remote services such as VPNs and remote desktops ensure that compromised passwords alone cannot grant adversary access to internal networks."},{"id":"T1134","name":"Access Token Manipulation","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Robust authentication that validates user identity beyond simple token presentation detects access token manipulation, as manipulated tokens fail to match the authenticated identity's authorization context."},{"id":"T1136","name":"Create Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Strong identification and authentication requirements ensure that only properly authenticated administrators can create new accounts, preventing adversaries from provisioning unauthorized identities for persistence."},{"id":"T1185","name":"Browser Session Hijacking","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Session-binding authentication mechanisms that validate user identity throughout browser sessions reduce the effectiveness of session hijacking by detecting identity mismatches during active sessions."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements on public-facing application endpoints restrict which users can reach vulnerable functionality, reducing the attack surface available for exploitation-based initial access."},{"id":"T1197","name":"BITS Jobs","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Requiring authentication for BITS transfer job creation ensures adversaries must first authenticate before scheduling background transfers for persistence or payload delivery."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Network-level authentication requirements on internal services ensure adversaries must present valid credentials before reaching potentially vulnerable service interfaces for lateral movement exploitation."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication mechanisms with proper cryptographic validation reduce the attack surface available for credential access exploitation by eliminating weak authentication protocols and implementations."},{"id":"T1213","name":"Data from Information Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Requiring unique user identification and strong authentication for information repositories ensures adversaries cannot access organizational knowledge bases, wikis, or document stores without verified credentials."},{"id":"T1218","name":"System Binary Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements at the system level ensure that only authenticated users can invoke system binaries, limiting adversary ability to use proxy execution techniques without valid credentials."},{"id":"T1222","name":"File and Directory Permissions Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Requiring authenticated and identified sessions before allowing permission modifications ensures adversaries must first prove their identity before attempting to weaken file and directory protections."},{"id":"T1484","name":"Domain or Tenant Policy Modification","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication for domain and tenant policy management interfaces prevents adversaries from modifying Group Policy or Azure AD policies without multi-factor-verified administrative credentials."},{"id":"T1489","name":"Service Stop","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements for service management operations ensure only properly identified administrators can stop critical services, preventing anonymous disruption of essential system functions."},{"id":"T1495","name":"Firmware Corruption","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Requiring strong authentication for firmware management interfaces prevents adversaries from corrupting device firmware without first establishing a verified administrative session."},{"id":"T1505","name":"Server Software Component","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Authentication controls on server administration interfaces prevent unauthorized installation of malicious server software components such as web shells, IIS modules, and transport agents."},{"id":"T1525","name":"Implant Internal Image","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on container registries and image management APIs ensures only verified users can push or modify container images, preventing unauthorized implantation of trojaned images."},{"id":"T1528","name":"Steal Application Access Token","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Robust authentication of application access requests, including OAuth consent verification and MFA challenges, limits adversary ability to steal or abuse application access tokens."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication on cloud storage access points ensures compromised credentials alone cannot be used to access cloud-hosted data stores, requiring additional identity verification."},{"id":"T1537","name":"Transfer Data to Cloud Account","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on cloud account management interfaces, including multi-factor identity verification and conditional access policies, prevents adversaries from configuring cross-account data transfers without completing verified administrative authentication workflows."},{"id":"T1538","name":"Cloud Service Dashboard","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication requirements for cloud management console access prevent adversaries from using stolen credentials alone to access service dashboards for infrastructure discovery."},{"id":"T1539","name":"Steal Web Session Cookie","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Session-level authentication validation and re-authentication requirements for sensitive operations reduce the utility of stolen web session cookies by enforcing ongoing identity verification."},{"id":"T1542","name":"Pre-OS Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements on BIOS/UEFI management interfaces and boot configuration tools prevent unauthorized modification of pre-OS boot components without verified administrator credentials."},{"id":"T1543","name":"Create or Modify System Process","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Requiring strong authentication for service creation and modification ensures adversaries must present verified administrative credentials before installing persistent system processes."},{"id":"T1548","name":"Abuse Elevation Control Mechanism","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication at privilege elevation boundaries ensures that elevation control mechanisms require verified identity before granting escalated privileges, not just a cached credential."},{"id":"T1550","name":"Use Alternate Authentication Material","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Strong primary authentication mechanisms that bind sessions to specific identity proofs make it harder for adversaries to use alternate authentication material like stolen hashes or tickets."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication renders unsecured credentials less exploitable, as discovered passwords or keys alone are insufficient for access when additional authentication factors are required."},{"id":"T1556","name":"Modify Authentication Process","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Authentication process integrity verification, including module signing and configuration monitoring, detects unauthorized modifications to authentication pipelines such as backdoored PAM modules or password filters."},{"id":"T1558","name":"Steal or Forge Kerberos Tickets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication mechanisms including AES-256 Kerberos encryption, managed service accounts, and certificate-based authentication make Kerberos ticket theft and forgery significantly more difficult by hardening the cryptographic foundations of ticket-granting services."},{"id":"T1559","name":"Inter-Process Communication","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements for inter-process communication channels ensure that COM objects and other IPC mechanisms only respond to properly authenticated callers, not arbitrary processes."},{"id":"T1562","name":"Impair Defenses","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Requiring strong authentication for security tool management ensures adversaries cannot disable or modify defensive tools without first authenticating with verified administrative credentials."},{"id":"T1563","name":"Remote Service Session Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Session-specific authentication and re-authentication requirements prevent adversaries from hijacking remote sessions, as each session connection must present valid credentials for the authenticated user."},{"id":"T1569","name":"System Services","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Requiring authenticated administrative access for system service management ensures only verified users can create or execute services through SCM or launchctl interfaces."},{"id":"T1574","name":"Hijack Execution Flow","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements on system administration functions prevent adversaries from modifying execution flow paths, library locations, or service configurations without proper credential verification."},{"id":"T1578","name":"Modify Cloud Compute Infrastructure","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on cloud compute management APIs through MFA and identity federation ensures adversaries cannot modify cloud infrastructure without multi-factor-verified administrative credentials."},{"id":"T1580","name":"Cloud Infrastructure Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Authentication and authorization on cloud infrastructure APIs ensure adversaries must authenticate with verified credentials before enumerating cloud resources, VPCs, and service configurations."},{"id":"T1599","name":"Network Boundary Bridging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements on network device management interfaces prevent unauthorized modification of network boundary configurations that could enable adversary traffic bridging between segments."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Requiring strong authentication for network device administration ensures adversaries cannot modify system images on routers and switches without verified administrative credentials."},{"id":"T1610","name":"Deploy Container","tactics":["defense-evasion","execution"],"mapping_type":"mitigates","mapping_rationale":"Authentication controls on container deployment APIs ensure only verified users can deploy containers, preventing adversaries from launching malicious workloads without proper identity verification."},{"id":"T1611","name":"Escape to Host","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Container runtime authentication controls restrict which authenticated users can modify container security boundaries, limiting adversary ability to escalate from container to host without proper credentials."},{"id":"T1613","name":"Container and Resource Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Requiring authentication on container orchestration discovery APIs ensures adversaries must present valid credentials before enumerating running containers and cluster resources."},{"id":"T1619","name":"Cloud Storage Object Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements on cloud storage APIs ensure adversaries must authenticate before listing or discovering storage objects, preventing unauthenticated enumeration of cloud data."},{"id":"T1621","name":"Multi-Factor Authentication Request Generation","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Phishing-resistant authentication methods such as FIDO2 and number-matching MFA make MFA fatigue attacks ineffective by requiring deliberate user interaction rather than simple approval taps."},{"id":"T1648","name":"Serverless Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on serverless function deployment and invocation APIs ensures adversaries cannot create or trigger Lambda/Cloud Functions without verified identity credentials."},{"id":"T1649","name":"Steal or Forge Authentication Certificates","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication mechanisms with certificate lifecycle management and hardware-backed key storage make it significantly harder for adversaries to steal or forge authentication certificates."},{"id":"T1651","name":"Cloud Administration Command","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication requirements for cloud administration command execution ensure adversaries cannot run infrastructure management commands against cloud resources with stolen single-factor credentials alone."},{"id":"T1003.001","name":"LSASS Memory","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Authentication mechanisms that reduce reliance on cached LSASS credentials, such as credential guard and MFA, limit the value of LSASS memory dumps by protecting credential material in hardware-backed containers."},{"id":"T1003.002","name":"Security Account Manager","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication renders SAM database password hashes less useful for adversary authentication, as extracted hashes alone cannot satisfy additional authentication factor requirements."},{"id":"T1003.003","name":"NTDS","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication requirements including MFA across the domain mean that NTDS.dit credential dumps provide only password hashes that are insufficient for complete authentication."},{"id":"T1003.004","name":"LSA Secrets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication on service accounts and interactive sessions reduces the value of LSA Secrets extracted from the registry, as cached credentials alone cannot complete authentication."},{"id":"T1003.005","name":"Cached Domain Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication that requires factors beyond cached domain credentials renders offline credential caches less valuable, as DCC2 hashes alone cannot satisfy MFA requirements."},{"id":"T1003.006","name":"DCSync","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Restricting DCSync-capable permissions and enforcing multi-factor authentication means that even if replication credentials are obtained, additional factors prevent their use for authentication."},{"id":"T1003.007","name":"Proc Filesystem","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Authentication mechanisms that avoid storing plaintext credentials in process memory, combined with MFA requirements, reduce the value of credential material extracted from /proc filesystem reads."},{"id":"T1003.008","name":"/etc/passwd and /etc/shadow","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication requiring factors beyond password hashes renders /etc/shadow contents less exploitable, as cracked passwords alone are insufficient when MFA is enforced."},{"id":"T1021.001","name":"Remote Desktop Protocol","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Requiring Network Level Authentication with multi-factor verification for RDP sessions ensures adversaries cannot connect to Remote Desktop services using stolen passwords alone."},{"id":"T1021.002","name":"SMB/Windows Admin Shares","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication requirements for SMB access, including NTLMv2 and Kerberos enforcement, prevent adversaries from authenticating to administrative shares with weak or relayed credentials."},{"id":"T1021.003","name":"Distributed Component Object Model","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Authentication controls on DCOM activation and access ensure adversaries must present valid credentials matching authorized identities before remotely invoking COM objects for lateral movement."},{"id":"T1021.004","name":"SSH","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Enforcing key-based SSH authentication with passphrase-protected keys and MFA integration prevents adversaries from establishing SSH sessions using stolen passwords or weak authentication methods."},{"id":"T1021.005","name":"VNC","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Requiring strong authentication for VNC sessions, including password complexity enforcement and MFA, prevents adversaries from accessing remote graphical sessions with weak or default credentials."},{"id":"T1021.006","name":"Windows Remote Management","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication requirements for WinRM sessions, combined with Kerberos-only authentication enforcement, ensure adversaries cannot execute remote PowerShell commands using only compromised password credentials for lateral movement."},{"id":"T1021.007","name":"Cloud Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Federated identity and multi-factor authentication on cloud service APIs ensure adversaries cannot laterally move through cloud services using single-factor credentials obtained from compromised systems."},{"id":"T1021.008","name":"Direct Cloud VM Connections","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on direct cloud VM access methods, including serial console and SSH, prevents adversaries from bypassing network security by authenticating to VMs with stolen credentials."},{"id":"T1036.007","name":"Double File Extension","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"User identification at the application level enables security tools to attribute file access and execution to authenticated users, allowing detection of double-extension file deception attempts."},{"id":"T1036.010","name":"Masquerade Account Name","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Strong identity verification during account creation prevents adversaries from registering accounts with masqueraded names that mimic legitimate users or service accounts."},{"id":"T1053.002","name":"At","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Requiring authentication for at command access ensures only verified users can schedule deferred command execution, preventing anonymous task creation for persistence."},{"id":"T1053.003","name":"Cron","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements for crontab modification ensure only properly identified users can create or edit cron jobs, preventing unauthorized scheduled task creation on Unix systems."},{"id":"T1053.005","name":"Scheduled Task","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication for Windows Task Scheduler access ensures only verified administrative accounts can create scheduled tasks, preventing adversary persistence through anonymous task scheduling."},{"id":"T1053.006","name":"Systemd Timers","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements for systemd timer management ensure only authorized and identified administrators can create timer-based persistent execution on Linux systems."},{"id":"T1053.007","name":"Container Orchestration Job","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"RBAC with strong authentication on container orchestration APIs ensures only verified users can create Kubernetes CronJobs, preventing unauthorized scheduled container workload creation."},{"id":"T1055.008","name":"Ptrace System Calls","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication and process isolation mechanisms restrict ptrace system call usage to authenticated debugging sessions owned by verified users, preventing unauthorized inter-process memory manipulation and code injection via ptrace."},{"id":"T1056.003","name":"Web Portal Capture","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on web portals with anti-tampering protections makes it harder for adversaries to inject credential-capturing overlays into legitimate authentication pages."},{"id":"T1059.001","name":"PowerShell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements for PowerShell remoting and Just Enough Administration sessions ensure adversaries must present valid multi-factor credentials before executing remote PowerShell commands on managed systems."},{"id":"T1059.008","name":"Network Device CLI","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on network device CLI interfaces, including TACACS+ and RADIUS with MFA, prevents adversaries from accessing device command lines with compromised single-factor credentials."},{"id":"T1059.009","name":"Cloud API","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication on cloud API endpoints ensures adversaries cannot execute cloud management commands using only stolen API keys or access tokens without additional verification."},{"id":"T1078.002","name":"Domain Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication for domain accounts ensures that compromised domain passwords alone are insufficient for adversary access, requiring additional identity verification factors."},{"id":"T1078.003","name":"Local Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Strong local authentication mechanisms, including complex password requirements and MFA for elevated access, limit the utility of compromised local account credentials for adversary operations."},{"id":"T1078.004","name":"Cloud Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Cloud-specific multi-factor authentication and conditional access policies ensure that stolen cloud credentials alone cannot grant adversary access without satisfying additional identity verification requirements."},{"id":"T1087.004","name":"Cloud Account","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on cloud directory and IAM enumeration APIs prevents unauthenticated adversary reconnaissance of cloud account inventories and identity structures."},{"id":"T1098.001","name":"Additional Cloud Credentials","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication for cloud identity management operations ensures adversaries cannot add additional credentials to cloud accounts without completing verified administrative authentication."},{"id":"T1098.002","name":"Additional Email Delegate Permissions","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication requirements for Exchange and M365 administration prevent adversaries from adding unauthorized email delegation without completing multi-factor identity verification."},{"id":"T1098.003","name":"Additional Cloud Roles","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"MFA-protected access to cloud IAM role management ensures adversaries cannot assign themselves elevated cloud permissions using only stolen administrative credentials."},{"id":"T1098.004","name":"SSH Authorized Keys","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication controls that monitor and validate SSH key changes, combined with MFA requirements for system access, detect and prevent unauthorized addition of SSH authorized keys."},{"id":"T1098.007","name":"Additional Local or Domain Groups","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication for group membership management operations ensures adversaries cannot modify local or domain group assignments without completing multi-factor identity verification."},{"id":"T1110.001","name":"Password Guessing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication renders password guessing attacks ineffective, as correctly guessed passwords cannot complete authentication without the additional required factors such as hardware tokens or biometrics."},{"id":"T1110.002","name":"Password Cracking","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication with MFA means that even successfully cracked password hashes cannot be used for authentication without additional factors, negating the value of offline cracking."},{"id":"T1110.003","name":"Password Spraying","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"MFA enforcement across all accounts makes password spraying ineffective, as discovering a valid username-password combination is insufficient to authenticate without the additional required factor."},{"id":"T1110.004","name":"Credential Stuffing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication ensures that credential stuffing with username-password pairs from data breaches fails, as stolen credentials from other services cannot satisfy additional authentication requirements."},{"id":"T1114.002","name":"Remote Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication requirements for remote email access, including modern authentication and MFA, prevent adversaries from accessing mailboxes using basic authentication with stolen credentials."},{"id":"T1134.001","name":"Token Impersonation/Theft","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous identity verification throughout authenticated sessions detects token impersonation by identifying mismatches between the manipulated token identity and the original authenticated user."},{"id":"T1134.002","name":"Create Process with Token","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication controls that bind process creation to verified user sessions detect attempts to create processes with manipulated tokens that do not match the session's authenticated identity."},{"id":"T1134.003","name":"Make and Impersonate Token","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Identity verification mechanisms detect fabricated impersonation tokens by validating that the claimed identity matches the authentication context of the session creating the token."},{"id":"T1136.001","name":"Local Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication requirements for local account creation ensure only verified administrators can provision new local accounts, preventing adversary establishment of backdoor identities."},{"id":"T1136.002","name":"Domain Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication for domain administration operations through privileged access workstations and tiered admin models ensures adversaries cannot create unauthorized domain accounts without completing full identity verification."},{"id":"T1136.003","name":"Cloud Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on cloud identity management APIs prevents adversaries from creating cloud accounts for persistence without verified multi-factor administrative authentication."},{"id":"T1213.001","name":"Confluence","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Requiring strong authentication for Confluence access ensures adversaries cannot browse organizational wiki content without presenting verified credentials and completing MFA challenges."},{"id":"T1213.002","name":"Sharepoint","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication on SharePoint access prevents adversaries from collecting documents and data using only stolen credentials without additional identity verification."},{"id":"T1213.003","name":"Code Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on code repository platforms, including SSH key verification and MFA, prevents adversary access to source code using compromised credentials alone."},{"id":"T1213.004","name":"Customer Relationship Management Software","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"MFA-protected access to CRM platforms ensures adversaries cannot extract customer relationship data without completing multi-factor identity verification beyond stolen passwords."},{"id":"T1213.005","name":"Messaging Applications","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on messaging platforms such as Slack and Teams prevents adversaries from accessing internal communications using only compromised SSO tokens or passwords."},{"id":"T1218.007","name":"Msiexec","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements at the system level ensure that msiexec execution for proxy purposes requires an authenticated session, preventing anonymous abuse of the Windows Installer."},{"id":"T1222.001","name":"Windows File and Directory Permissions Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"User identification ensures that permission modifications on Windows are attributed to authenticated users, enabling detection and restriction of unauthorized ACL changes."},{"id":"T1222.002","name":"Linux and Mac File and Directory Permissions Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements on Linux and macOS ensure that chmod and chown operations are attributed to verified users, enabling enforcement of permission modification restrictions."},{"id":"T1505.002","name":"Transport Agent","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication for Exchange administration prevents unauthorized installation of transport agents, as adversaries must first authenticate with verified administrative credentials."},{"id":"T1505.004","name":"IIS Components","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication for IIS administration interfaces and server management consoles ensures adversaries cannot register malicious IIS components such as ISAPI filters or managed modules without completing multi-factor identity verification."},{"id":"T1542.001","name":"System Firmware","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements on UEFI/BIOS management interfaces, including firmware setup passwords and Secure Boot enrollment verification, prevent unauthorized modification of system firmware without verified administrative access."},{"id":"T1542.003","name":"Bootkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Secure Boot with authenticated boot chain verification ensures that only cryptographically signed boot components can execute, preventing unauthenticated bootkit installation."},{"id":"T1542.005","name":"TFTP Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements on network device boot configuration prevent unauthorized modification of TFTP boot settings that could redirect devices to adversary-controlled boot images."},{"id":"T1543.001","name":"Launch Agent","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication controls restricting which users can install launch agents on macOS ensure adversaries must authenticate with valid credentials before establishing agent-based persistence."},{"id":"T1543.002","name":"Systemd Service","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication for systemd service management ensures only verified users with administrative credentials can create or modify systemd services for persistence."},{"id":"T1543.003","name":"Windows Service","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication for Windows service management through privilege access management tools ensures adversaries cannot create persistent Windows services without completing verified multi-factor administrative authentication."},{"id":"T1543.004","name":"Launch Daemon","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements for launch daemon installation ensure only verified root users can install LaunchDaemons, preventing adversary persistence through unauthorized daemon creation."},{"id":"T1543.005","name":"Container Service","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on container orchestration APIs with RBAC ensures only verified administrators can create or modify container services for persistent workload deployment."},{"id":"T1546.003","name":"Windows Management Instrumentation Event Subscription","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements for WMI administration prevent adversaries from creating persistent WMI event subscriptions without first authenticating with verified administrative credentials."},{"id":"T1547.004","name":"Winlogon Helper DLL","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication for administrative registry modification ensures adversaries must present verified multi-factor credentials before modifying Winlogon Helper DLL references used for persistent code loading during logon."},{"id":"T1547.006","name":"Kernel Modules and Extensions","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements for kernel module operations ensure only verified administrators can load or install kernel modules and extensions for persistent privileged access."},{"id":"T1547.009","name":"Shortcut Modification","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"User identification enables detection of unauthorized shortcut modifications by attributing file system changes to authenticated users and flagging modifications by unexpected identities."},{"id":"T1547.012","name":"Print Processors","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication for print spooler administration and registry modification ensures adversaries must authenticate with verified multi-factor credentials before registering malicious print processor DLLs for persistent execution."},{"id":"T1547.013","name":"XDG Autostart Entries","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication controls on Linux desktop environment administration ensure only verified users with proper credentials can create XDG autostart entries in user or system autostart directories for persistence."},{"id":"T1548.002","name":"Bypass User Account Control","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication enforcement at UAC prompts, including credential entry requirements rather than consent-only prompts, prevents adversaries from silently bypassing elevation controls."},{"id":"T1548.003","name":"Sudo and Sudo Caching","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Re-authentication requirements at sudo prompts with short or no timeout caching ensure adversaries must re-verify identity for each privileged command, preventing sudo cache abuse."},{"id":"T1550.001","name":"Application Access Token","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Continuous authentication validation ensures that application access tokens are verified against the authenticated identity at each use, detecting tokens obtained through unauthorized means."},{"id":"T1550.002","name":"Pass the Hash","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication requirements prevent pass-the-hash attacks from succeeding, as NTLM hash presentation alone is insufficient when additional authentication factors are required."},{"id":"T1550.003","name":"Pass the Ticket","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication with PAC validation and ticket lifetime enforcement detects pass-the-ticket attacks by verifying that presented Kerberos tickets were legitimately issued by the KDC."},{"id":"T1552.001","name":"Credentials In Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication renders credentials found in files less exploitable, as discovered passwords or keys alone are insufficient for authentication when additional factors are required."},{"id":"T1552.002","name":"Credentials in Registry","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"MFA requirements ensure that credentials extracted from Windows Registry entries cannot be used for authentication without additional factors, limiting the impact of registry credential discovery."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication requirements beyond key-based access ensure that stolen private keys alone are insufficient for authentication when additional identity verification is required."},{"id":"T1552.006","name":"Group Policy Preferences","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"MFA enforcement means that credentials found in Group Policy Preferences XML files cannot be used for authentication without satisfying additional factor requirements."},{"id":"T1552.007","name":"Container API","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on container APIs ensures that credentials discovered through container metadata queries cannot be directly used for escalated access without additional verification."},{"id":"T1555.005","name":"Password Managers","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication ensures that credentials extracted from password managers cannot be used for system access without satisfying additional authentication factors."},{"id":"T1556.001","name":"Domain Controller Authentication","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Integrity verification of domain controller authentication components and multi-layer authentication ensure that backdoored DC authentication processes are detected and cannot bypass identity verification."},{"id":"T1556.003","name":"Pluggable Authentication Modules","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Authentication integrity monitoring detects unauthorized PAM module modifications by verifying that pluggable authentication components match approved configurations and cryptographic signatures."},{"id":"T1556.004","name":"Network Device Authentication","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication on network device access ensures that even compromised local authentication mechanisms cannot grant access without additional identity verification factors."},{"id":"T1556.006","name":"Multi-Factor Authentication","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Phishing-resistant MFA mechanisms such as FIDO2 and certificate-based authentication are resilient to MFA modification attacks because they rely on cryptographic operations rather than modifiable server-side logic."},{"id":"T1556.007","name":"Hybrid Identity","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Authentication integrity controls on hybrid identity synchronization detect unauthorized modifications to on-premises-to-cloud authentication flows that could allow adversary identity spoofing."},{"id":"T1556.009","name":"Conditional Access Policies","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"MFA-protected access to conditional access policy management in Azure AD and other identity providers prevents adversaries from weakening or disabling authentication requirements without completing multi-factor verified administrative authentication."},{"id":"T1558.001","name":"Golden Ticket","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication with AES-256 Kerberos encryption and regular krbtgt key rotation reduces the utility of golden ticket forgery by limiting ticket lifetime and increasing cryptographic complexity."},{"id":"T1558.002","name":"Silver Ticket","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Service account authentication hardening with complex passwords and AES encryption makes silver ticket forgery computationally difficult by requiring adversaries to crack strong encryption keys."},{"id":"T1558.003","name":"Kerberoasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong service account authentication with managed service accounts and AES encryption makes Kerberoasting attacks less viable by eliminating weak RC4-encrypted service tickets."},{"id":"T1558.004","name":"AS-REP Roasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Enforcing Kerberos pre-authentication for all accounts ensures that AS-REP responses cannot be obtained for offline cracking, as the KDC requires proof of identity before issuing tickets."},{"id":"T1558.005","name":"Ccache Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication with short ticket lifetimes and regular credential rotation reduces the window during which stolen ccache files contain usable Kerberos tickets."},{"id":"T1559.001","name":"Component Object Model","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements for COM activation ensure that only processes running under properly authenticated user contexts can invoke COM objects for inter-process code execution."},{"id":"T1562.001","name":"Disable or Modify Tools","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication for security tool administration consoles and configuration interfaces prevents adversaries from disabling antivirus, EDR, or other protective software without completing verified multi-factor identity checks."},{"id":"T1562.002","name":"Disable Windows Event Logging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Strong multi-factor authentication for audit policy management and event log service administration ensures adversaries cannot disable Windows event logging without completing verified administrative identity checks."},{"id":"T1562.004","name":"Disable or Modify System Firewall","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements for firewall management interfaces and network security administration ensure adversaries must verify their identity through multi-factor authentication before disabling or modifying host-based firewall rules."},{"id":"T1562.006","name":"Indicator Blocking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication for security sensor management and ETW provider configuration prevents adversaries from blocking telemetry indicators or disabling security monitoring without completing verified administrative authentication."},{"id":"T1562.007","name":"Disable or Modify Cloud Firewall","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Strong multi-factor authentication on cloud security group management consoles and APIs ensures adversaries cannot modify or disable cloud-based network firewall rules without verified multi-factor credentials."},{"id":"T1562.008","name":"Disable or Modify Cloud Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"MFA-protected access to cloud logging service administration prevents adversaries from disabling CloudTrail, Cloud Audit Logs, or other cloud logging without verified identity."},{"id":"T1562.009","name":"Safe Mode Boot","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements for boot configuration changes prevent adversaries from rebooting into Safe Mode without first proving their identity through verified administrative credentials."},{"id":"T1563.001","name":"SSH Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Strong SSH authentication with unique session keys and re-authentication requirements prevents adversaries from taking over existing SSH sessions by exploiting forwarded agents or multiplexed connections."},{"id":"T1563.002","name":"RDP Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Session-specific authentication and reconnection credential requirements prevent adversaries from hijacking disconnected RDP sessions, as each reconnection must present valid credentials."},{"id":"T1569.001","name":"Launchctl","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements for launchctl operations ensure only verified users can load, unload, or manage macOS services through the launchctl interface."},{"id":"T1569.002","name":"Service Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication for service control manager operations ensures adversaries must present verified administrative credentials before executing code through Windows service mechanisms."},{"id":"T1574.005","name":"Executable Installer File Permissions Weakness","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication requirements for file system modification ensure adversaries must authenticate before exploiting installer file permission weaknesses to replace legitimate executables."},{"id":"T1574.010","name":"Services File Permissions Weakness","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication for service configuration changes ensures adversaries must verify their identity before exploiting services file permissions to hijack service execution."},{"id":"T1574.012","name":"COR_PROFILER","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authentication controls on .NET configuration and environment variable modification prevent adversaries from setting COR_PROFILER values to load malicious profiler DLLs without first completing authenticated administrative access."},{"id":"T1578.001","name":"Create Snapshot","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Multi-factor authentication on cloud snapshot creation APIs ensures adversaries cannot create VM snapshots for data extraction without verified administrative credentials."},{"id":"T1578.002","name":"Create Cloud Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Strong multi-factor authentication on cloud instance deployment APIs prevents adversaries from launching new virtual machines in unmonitored regions or accounts without completing multi-factor-verified credential presentation."},{"id":"T1578.003","name":"Delete Cloud Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"MFA requirements for cloud instance deletion prevent adversaries from destroying virtual machines using stolen credentials that cannot satisfy additional authentication factors."},{"id":"T1599.001","name":"Network Address Translation Traversal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication on network device management prevents adversaries from modifying NAT configurations to bridge network boundaries without verified administrative identity."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Authentication controls on network device firmware update mechanisms, including TACACS+ verification and multi-factor administrative access, ensure adversaries cannot patch system images without verified credentials."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication for firmware downgrade operations ensures adversaries cannot roll back network device images to vulnerable versions without verified administrative access."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-005","SP-006","SP-007","SP-011","SP-013","SP-015","SP-017","SP-021","SP-022","SP-023","SP-028","SP-029","SP-030","SP-032","SP-033","SP-034","SP-037","SP-041","SP-044","SP-048","SP-050","SP-052","SP-054"]}}