Modify Authentication Process: Hybrid Identity

Description

Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises user identities in order to bypass typical authentication mechanisms, access credentials, and enable persistent access to accounts.

Products, Sensors, and Dependencies

ProductDependenciesData sourceAccess requiredProtocolData CollectedNotes
Tenable Identity ExposureEntra IDRead-onlyHTTPSAzure Users
Tenable Identity ExposureActive DirectoryStandard AD UserLDAPList of Domain Computers and Users
Tenable Vulnerability ManagementAD Start or Identity ScanActive DirectoryAuthenticated AD UserLDAPList of Domain Users Plugin ID: 167250

Attack Path Technique Details

Framework: MITRE ATT&CK

Family: Credential Access, Defense Evasion, Persistence

Sub-Technique: Hybrid Identity

Platform: Entra ID

Products Required: Tenable Identity Exposure

Tenable Release Date: 2024 Q3