A.8.5 Technological
Secure authentication
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (25)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-12mostlyaligns with — Both controls require automatic termination of sessions after a defined period of inactivity to reduce exposure on unattended or high-risk endpoints.
- AC-7mostlyaligns with — Both controls mandate technical measures to limit or block repeated unsuccessful log-on attempts and to trigger security events when thresholds are exceeded.
- IA-2mostlyaligns with — Both controls require authentication mechanisms whose strength is commensurate with the sensitivity of the resources being accessed and explicitly call for multi-factor authentication when stronger assurance is needed.
- IA-2mostlycovers — IA-5 (Authenticator Management) -> A.5.17 is the calibrated anchor for this exact direction and grades mostly; A.8.5's secure-authentication requirements (MFA, credential protections, logon procedures) are substantially but not fully accounted for by IA-2's narrower focus on unique identification plus association with processes.
- IA-5mostlyaligns with — Both controls address the secure management and protection of authenticators, including rules for password handling, transmission, and the invalidation of compromised credentials such as biometrics.
- IA-5mostlycovers — IA-5's requirements for initial distribution verification, content establishment, strength, and (implied continuation) management are almost entirely accounted for by A.8.5's mandate to ensure secure authentication, but A.8.5 leaves some residual on non-user entities and detailed lifecycle procedures that sit outside its core focus.
- AC-8partialaligns with — Both controls require the presentation of a general warning banner or notice that only authorized users may access the system before authentication completes.
- AC-9partialaligns with — Both controls require the system to display or transmit the date/time of the last successful log-on and details of any intervening unsuccessful attempts upon successful authentication.
- IA-6partialaligns with — Both controls require that passwords or other authenticators are not displayed in clear text during entry to prevent shoulder-surfing or capture.
- AC-12covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- AC-9covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- IA-6covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (18)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-03fullcovers — The ISO control directly mandates authentication of users, services, and hardware using techniques whose strength matches the sensitivity of the information being accessed.
- PR.AA-01mostlyaligns with — The control addresses management of identities and credentials by specifying how authentication information must be protected, reset, and supplemented with additional factors.
- PR.AA-02mostlyaligns with — Requiring identity proofing and binding to credentials is implicit in the control’s emphasis on choosing appropriate authentication methods and invalidating compromised biometrics.
- PR.AA-05partialaligns with — Multi-factor rules triggered by context (location, device, time) and session termination after inactivity both enforce and review access authorizations.
- PR.IR-01partialaligns with — By preventing brute-force attacks, hiding sensitive information until authentication succeeds, and terminating inactive sessions, the control contributes to protecting networks and environments from unauthorized logical access.
- PR.PS-04partialaligns with — The control requires logging of successful and unsuccessful log-on attempts and raising security events when thresholds are exceeded, directly supporting log-record generation.
- PR.AA-01implements — A.8.5 directly operationalizes secure authentication of identities/credentials, which is the core subject PR.AA-01 requires the organization to manage
- PR.AA-02implements — A.8.5's operational focus on secure authentication directly operationalizes the identity-proofing and credential-binding outcome in PR.AA-02 within the access/identity domain, though the CSF outcome does not name authentication mechanisms specifically
- PR.AA-05implements — A.8.5 directly operationalizes the enforcement half of PR.AA-05 by providing the secure authentication mechanism that carries out defined and managed access decisions.
- PR.IR-01implements — A.8.5's secure authentication mechanisms give operational effect to protecting networks/environments from unauthorized logical access (PR.IR-01), as authentication is a core technical means within that domain (though not the only one).
- PR.PS-04implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (15)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V6.2.6fullaligns with — The explicit instruction not to display passwords in clear text during entry matches the ASVS requirement that password fields use type=password to mask input.
- V7.3.1fullaligns with — The ISO directive to terminate inactive sessions after a defined period of inactivity implements the ASVS requirement for an inactivity timeout that forces re-authentication.
- V6.3.1mostlycovers — Guidance on blocking accounts or forcing resets after repeated failed attempts and on raising alerts for suspicious log-on patterns aligns with the ASVS requirement to implement documented controls against brute-force and credential-stuffing attacks.
- V6.3.3mostlycovers — The ISO control's requirement for multi-factor authentication when accessing critical systems directly implements the ASVS mandate that MFA or equivalent combined single-factor mechanisms must be used to reach high-value resources.
- V6.3.5partialaligns with — Sending alerts to users and administrators when a threshold of failed log-on attempts is reached partially satisfies the ASVS requirement to notify users of suspicious authentication attempts.
- V6.3.8partialaligns with — The rule that error messages must not reveal which part of the supplied credentials is correct or incorrect supports the ASVS goal of preventing attackers from deducing valid usernames from authentication feedback.
- V6.4.3partialaligns with — Requiring a secure password-reset process that does not bypass MFA when biometric or other factors are unavailable aligns with the ASVS requirement for a secure forgotten-password flow that preserves existing MFA protections.
Related weaknesses / CWE (137)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-187noneprevents — Secure authentication mechanisms can reduce reliance on partial string comparisons for credential or token validation.
- CWE-346noneprevents — Secure authentication verifies identity but does not address origin validation of arbitrary data flows.
- CWE-348nonemitigates — Strong authentication mechanisms ensure data originates from a trusted source, directly mitigating use of a less-trusted source.
- CWE-441nonemitigates — Strong authentication of upstream callers helps the product verify and preserve the true source of each request.
- CWE-757nonemitigates — Requires secure authentication mechanisms that typically rely on strong negotiated algorithms.
- CWE-916nonemitigates — Mandates secure authentication mechanisms, directly addressing the need for computationally strong password hashes.
- CWE-1191mitigates — Secure authentication concepts apply to debug interfaces but the control focuses on user/system log-on.
- CWE-1270prevents — Secure authentication mechanisms directly govern the correct generation and validation of security tokens.
- CWE-1390prevents — Mandating multi-factor and non-password authentication techniques counters the use of inherently weak single-factor or password-only authentication mechanisms.
- CWE-1391prevents — Mandates secure authentication mechanisms that preclude use of weak or default credentials.
- CWE-1393mitigates — Requires secure authentication mechanisms, which includes replacing or disabling default credentials.
- CWE-200prevents — Suppressing system details, error specifics, and previous log-on information until successful authentication reduces the information an unauthenticated attacker can gather.
- CWE-204prevents — Strong authentication reduces information leakage from authentication responses.
- CWE-257prevents — Mandates secure authentication mechanisms that preclude recoverable password storage.
- CWE-258prevents — Mandates secure authentication mechanisms, preventing use of empty or weak passwords.
- CWE-287prevents — Requiring authentication methods whose strength matches the sensitivity of the data and mandating multi-factor authentication directly blocks attempts to access resources without proving identity.
- CWE-288prevents — Secure authentication control directly mitigates bypass by requiring strong, consistent authentication on all paths.
- CWE-289prevents — Secure-authentication controls can require canonical identifiers and reject alternate names.
- CWE-290prevents — Secure authentication control directly mitigates authentication bypass by spoofing.
- CWE-291prevents — Secure-authentication control directly addresses the weakness by requiring proper credentials instead of IP address.
- CWE-293prevents — Secure authentication explicitly requires strong, non-spoofable mechanisms, directly preventing reliance on the Referer header.
- CWE-294prevents — Secure authentication mechanisms directly prevent replay attacks by requiring fresh, non-replayable credentials or tokens.
- CWE-298prevents — Secure authentication mandates validation of certificate attributes such as expiration dates.
- CWE-299prevents — Requires secure authentication mechanisms that rely on valid certificates.
- CWE-300prevents — Secure authentication mechanisms verify actor identity at both ends of the channel.
- CWE-301prevents — Secure authentication mechanisms directly address reflection attacks by requiring challenge-response designs that prevent replay of authentication tokens.
- CWE-302prevents — Secure authentication explicitly requires server-side validation of all identity claims, directly eliminating this weakness.
- CWE-303prevents — Secure authentication control directly requires correct implementation of authentication algorithms.
- CWE-304prevents — Mandates secure authentication mechanisms, explicitly addressing missing steps in authentication flows.
- CWE-305prevents — Secure authentication mechanisms directly address bypass risks in the implemented authentication process.
- CWE-306prevents — The control explicitly calls for authentication before any critical function is reached, eliminating the possibility of bypassing authentication for high-value operations.
- CWE-307prevents — CAPTCHA, account lock-out after repeated failures, and alerts on excessive attempts directly stop automated brute-force guessing of credentials.
- CWE-308prevents — Secure authentication control explicitly requires multi-factor authentication, directly eliminating single-factor weakness.
- CWE-309prevents — Secure authentication control directly requires and guides non-password or hardened password mechanisms.
- CWE-322prevents — Secure authentication directly prevents unauthenticated key exchange by requiring verified identities before keys are established.
- CWE-334mitigates — Secure authentication mechanisms often rely on unpredictable tokens or nonces, so weak randomness undermines them.
- CWE-340prevents — Secure authentication mechanisms depend on unpredictable session tokens, nonces and challenges; eliminating predictable identifiers strengthens authentication integrity.
- CWE-341prevents — Strong authentication mechanisms reduce reliance on predictable state-derived tokens or identifiers.
- CWE-345prevents — Secure authentication of data sources ensures only valid, authentic data is accepted.
- CWE-350prevents — Strong authentication mechanisms reduce reliance on unauthenticated DNS-based identity decisions.
- CWE-358prevents — Secure authentication control may be undermined if the underlying protocol checks are improperly implemented.
- CWE-370mitigates — Secure authentication mandates certificate validation, but does not explicitly require ongoing revocation checks after initial validation.
- CWE-408prevents — Secure authentication ensures identity verification occurs before expensive operations are allowed.
- CWE-419prevents — Secure authentication protects the primary channel from unauthorized use.
- CWE-420prevents — Secure authentication applies to primary channels but does not ensure alternate channels receive the same strength.
- CWE-421prevents — Strong authentication on all channels prevents unauthorized actors from using alternate paths.
- CWE-424mitigates — Secure authentication helps but does not guarantee every alternate path is protected.
- CWE-522prevents — Forbidding clear-text transmission and display of passwords, plus the use of stronger alternatives to passwords, prevents credentials from being obtained or reused by attackers.
- CWE-565prevents — Secure authentication mechanisms can enforce server-side validation and integrity checks that prevent reliance on untrusted cookies.
- CWE-6prevents — Secure authentication mandates sufficiently strong session identifiers, directly addressing insufficient session-ID length.
- CWE-603prevents — Requires server-side authentication mechanisms that directly prevent client-only checks.
- CWE-620prevents — Mandates secure authentication mechanisms, which include verifying existing credentials before permitting password changes.
- CWE-640mitigates — Secure-authentication requirements include robust forgotten-password procedures.
- CWE-642prevents — Strong authentication helps ensure only legitimate users can reach the state data, but does not address storage location.
- CWE-654prevents — Secure authentication explicitly requires multi-factor authentication, directly eliminating single-factor reliance.
- CWE-656prevents — Requires authentication mechanisms whose strength does not depend on secrecy of implementation.
- CWE-759prevents — Secure authentication mandates salted, one-way hashes for credentials, directly preventing unsalted hashing.
- CWE-760prevents — Secure authentication mandates strong credential storage practices, directly addressing predictable salts in password hashing.
- CWE-784prevents — Secure authentication mandates validation of session tokens, directly addressing reliance on unverified cookies.
- CWE-804prevents — Strong authentication mechanisms include robust CAPTCHA implementations that resist automated guessing.
- CWE-807prevents — Strong authentication mechanisms reduce reliance on untrusted inputs for security decisions.
- CWE-836prevents — Mandates secure authentication mechanisms that preclude the flawed practice of treating password hashes as authenticators.
- CWE-923prevents — Secure authentication mechanisms ensure the product communicates only with intended, authenticated endpoints.
- CWE-940prevents — Secure authentication mechanisms verify the identity and origin of communication channel initiators.
Mitigated MITRE ATT&CK techniques (1076)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1003detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior activity; this surfaces anomalous credential-use patterns consistent with post-dump lateral movement but does not instrument or surface the OS-level dumping act itself (memory scraping, LSASS access, etc.).
- T1003prevents — A.8.5 mandates strong/MFA authentication, log-on protections against brute-force, no cleartext passwords in transit or display, session termination, and alerts on failed attempts — all of which stop many T1003 paths that rely on weak or captured credentials from yielding usable access, though not the initial memory/OS-cache dump itself.
- T1003.001detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior failed attempts on next successful log-on; these surface anomalous credential-access activity tied to LSASS but only for the log-on slice of the technique, not memory dumping, SSP modification, or in-memory harvesting itself.
- T1003.001prevents — A.8.5 mandates strong/multi-factor authentication techniques, log-on protections against brute-force and credential exposure, session termination, and non-cleartext handling, which directly prevent many LSASS credential-harvesting vectors (e.g., weak logons, SSP additions, plaintext exposure) that rely on insufficient authentication strength or post-logon credential material; the bounded remainder is in-memory dumping by already-privileged SYSTEM/administrative processes after a successful logon.
- T1003.002detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or brute-force patterns, and monitoring for anomalous access (unusual location/device/time) that can surface credential-dumping activity once SYSTEM-level access is obtained and the technique runs.
- T1003.002prevents — A.8.5 mandates strong/multi-factor authentication, log-on protections against brute-force, MFA on critical systems, session termination, and no cleartext passwords, which stops most credential material extracted from SAM from being usable for unauthorized access (the technique's end goal); the named remainder is local SYSTEM-level extraction that can still succeed before any authentication check occurs.
- T1003.003detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches (e.g. repeated failures), and separate-channel notifications of prior activity, which can surface anomalous credential access or NTDS dumping attempts that involve authentication; this is a genuine but minority slice of the technique's execution (most steps use Volume Shadow Copy, ntdsutil, etc. with no logon involved).
- T1003.003prevents — A.8.5 mandates strong/MFA authentication, protected log-on procedures, brute-force defenses, session termination, and no cleartext credential transmission, which stops many paths to credential theft via NTDS access but leaves the technique possible once an authenticated session or privileged process is already active on a DC.
- T1003.004detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and separate-channel notification of prior failed attempts; this surfaces anomalous credential-access activity that can indicate LSA secrets dumping but only for the subset tied to log-on events rather than direct registry/memory access post-SYSTEM compromise.
- T1003.004prevents — A.8.5 mandates strong/MFA authentication, protected log-on procedures, brute-force defenses, session termination, and non-cleartext credential handling, which largely stops the credential material in LSA secrets from being useful for unauthorized access even if extracted.
- T1003.005detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior log-on details; these surface anomalous credential-access activity (including cached-domain extraction by tools like Mimikatz) once it triggers a log-on or related event, but the control's scope is limited to authentication events rather than the full breadth of credential dumping from caches, SSSD files, or registry locations.
- T1003.005prevents — A.8.5 mandates strong/multi-factor authentication, failed-attempt limits, session termination, and non-cleartext handling that stop cached-domain hashes from being useful for unauthorized access or cracking in most scenarios; the bounded remainder is offline extraction by already-privileged (SYSTEM/sudo) actors who bypass auth entirely.
- T1003.006detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, and monitoring for anomalous access patterns (unusual location/device/time), which can surface DCSync attempts that abuse privileged replication APIs or produce detectable log artifacts, but this is only a slice as the technique often runs with valid high-privilege credentials without triggering logon events or anomalies.
- T1003.006prevents — A.8.5 mandates strong/MFA authentication, log-on protections against brute-force, session termination, and no cleartext passwords, which can prevent many credential-theft vectors that enable DCSync; however, it does not address the core privilege model (Admin/Domain Admin rights on a DC) or replication API abuse once those rights exist, leaving a large named remainder of the technique untouched.
- T1003.007prevents — A.8.5 mandates strong/MFA authentication, protected log-on procedures, brute-force defenses, session termination, and no cleartext credential transmission, which stops many credential-gathering techniques from yielding usable access; however, it does not address in-memory credential storage patterns or procfs memory scraping itself once a process is already authenticated or running with sufficient rights.
- T1003.008detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and displaying prior failed attempts on next successful log-on; these surface the technique when it is performed by an already-authenticated (or root) user, but the control's scope is limited to authentication events and does not broadly instrument file-access or dumping of /etc/shadow by other means.
- T1003.008prevents — A.8.5 mandates strong/MFA authentication, failed-attempt limits, session termination, and non-cleartext handling that stop many paths to root-level read access needed for /etc/shadow dumping; the bounded remainder is already-privileged local users or kernel-level bypasses that the clause does not reach.
- T1021detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or thresholds (e.g. repeated failures), and notifying on prior failed attempts, which surfaces T1021 use of valid accounts over remote services; this is only a slice because the clause governs authentication flows rather than mandating broad behavioral monitoring of post-auth remote sessions or lateral movement.
- T1021prevents — A.8.5 mandates strong, MFA, brute-force protection, session termination and log-on hardening that stop most uses of stolen credentials over remote services; the bounded remainder is already-compromised credentials that satisfy all factors plus legitimate admin tools that are allowed to use the same protocols.
- T1021.001detects — A.8.5 explicitly requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches (e.g. repeated failures), and notifying on prior failed attempts, which surfaces RDP logon abuse by valid accounts; this is only a slice because the clause governs authentication UX rather than mandating comprehensive RDP-specific or post-authentication behavioral monitoring.
- T1021.001prevents — A.8.5 mandates MFA, brute-force protections, session termination, non-cleartext transmission, and log-on hardening that stop an adversary with stolen credentials (or guessing them) from successfully authenticating over RDP; the named remainder is legacy/service accounts exempted from MFA or environments where RDP is allowed without those controls.
- T1021.002detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and notifying on prior failed attempts, which surfaces anomalous use of valid accounts over SMB/admin shares; this is a genuine but minority slice because the control is scoped only to authentication events rather than the full range of SMB lateral movement artifacts (e.g. file access patterns, RPC execution, or Pass-the-Hash without failed logons).
- T1021.002prevents — A.8.5 mandates strong, MFA, brute-force protection, session termination and non-cleartext auth that stop most SMB/Windows Admin Share access attempts relying on stolen/weak/guessable credentials or sessions; the bounded remainder is pass-the-hash with already-compromised NTLM material that bypasses the authentication factors themselves.
- T1021.003detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior activity; this surfaces anomalous DCOM use of valid accounts but only for the authentication/logon slice, not the subsequent remote COM/RPC execution or object interaction itself.
- T1021.003prevents — A.8.5 mandates strong, MFA-based authentication (with brute-force protection, session termination, and logon hardening) proportionate to data classification; this directly stops adversaries from obtaining or using the valid accounts required to authenticate and activate DCOM remotely, though it leaves a bounded remainder for already-compromised credentials, local-only DCOM, or exempted high-privilege service accounts.
- T1021.004detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and notifying on prior failed attempts, which surfaces SSH login abuse by valid accounts; this is limited to a slice because the control is scoped to authentication events rather than full SSH session monitoring or post-authentication actions.
- T1021.004prevents — A.8.5 directly governs selection and enforcement of suitable/strong authentication techniques (MFA, keypairs over passwords, brute-force protections, no cleartext transmission, session termination) that stop an adversary from successfully using a valid account over SSH, with a bounded remainder for exempted/legacy identities and configurations allowed by the clause itself.
- T1021.005detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. brute-force thresholds), and separate-channel notifications of prior failed attempts, which surfaces VNC abuse that relies on valid accounts or brute-forceable auth; this is only a slice because the clause is scoped to log-on procedures rather than ongoing VNC session monitoring or the full range of post-auth remote-control behaviors.
- T1021.005prevents — A.8.5 mandates strong, MFA-capable authentication (with brute-force protections, no cleartext transmission, session termination, etc.) whose strength matches the classification of information accessed; this directly stops the adversary's use of valid accounts over VNC in the bulk of cases, with a nameable remainder for legacy VNC configs, exempted accounts, or implementations that still allow weak auth.
- T1021.006detects — A.8.5 explicitly requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior logon details, which surfaces anomalous or unauthorized WinRM use of valid accounts; this is only a slice because the clause scopes to authentication events rather than all post-auth WinRM protocol activity or non-logon artifacts.
- T1021.006prevents — A.8.5 mandates strong, MFA, brute-force protection, session termination and logon hardening that stop an adversary from successfully using a stolen or guessed credential over WinRM; the named remainder is already-compromised accounts that satisfy all authentication factors.
- T1021.007detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and notifying on prior failed attempts, which surfaces adversary use of valid accounts to access cloud services; this is limited to a slice because the control is scoped to log-on procedures rather than all authentication vectors (e.g. application access tokens) or post-auth cloud CLI/API usage.
- T1021.007prevents — A.8.5 mandates MFA, strong auth methods, brute-force protections, session termination, and logon hardening that stop most uses of stolen/federated credentials or tokens against cloud services; the bounded remainder is already-compromised on-premises identities or application tokens that bypass these when federation is the authoritative source.
- T1021.008detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and notifying on prior failed attempts, which surfaces the use of this interactive direct VM connection technique when it occurs.
- T1021.008prevents — A.8.5 mandates strong, MFA-capable authentication techniques, log-on hardening (brute-force protection, no cleartext, session termination, alerts), and strength proportionate to sensitivity; this directly stops most password/token/SSH-key abuse paths for direct cloud VM logins, with a bounded remainder of legacy or exempted identities that the clause itself names.
- T1037detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and displaying prior log-on details, which surfaces anomalous or unauthorized use of logon-initialization vectors on covered platforms; this is only a slice because the control is scoped to authentication events rather than all boot-time script execution or remote initialization.
- T1037prevents — A.8.5's MFA, strong auth, log-on hardening (brute-force protection, no cleartext, session termination, separate-channel last-logon info) and credential-protection measures stop adversaries from obtaining the local/admin credentials needed to plant or abuse boot/logon initialization scripts on most platforms.
- T1037.001detects — A.8.5 explicitly requires logging of successful/unsuccessful logon attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior logon details, which surfaces anomalous logon-script execution at the authentication boundary; this is only a slice of the full technique (e.g., no coverage of registry modification or non-logon persistence aspects).
- T1037.001prevents — A.8.5 mandates strong/MFA logon procedures, failed-attempt limits, session termination, and warnings that can block unauthorized logons needed to plant or trigger the UserInitMprLogonScript Registry value; this stops the technique for many users but leaves a nameable remainder (privileged/admin accounts, already-compromised sessions, or non-interactive persistence paths) where the control's requirements do not reach.
- T1037.002detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and notifying on anomalies like prior failed attempts, which surfaces suspicious Login Hook activity at logon time on macOS; this is a genuine but minority slice of the technique's full attack surface (modification of the plist requires admin privileges outside logon, and the technique is deprecated post-10.11).
- T1037.002prevents — A.8.5's strong/multi-factor authentication, log-on procedure hardening (no info leakage, brute-force protection, session termination, no cleartext passwords), and alerts on failed logons raise the bar for an adversary to obtain the admin privileges needed to write the login hook plist, but do not stop a privileged user or bypassed auth from doing so, and the technique itself is a post-auth persistence mechanism.
- T1037.003detects — A.8.5 explicitly requires logging of successful/unsuccessful logons, raising security events/alerts on detected breaches or brute-force patterns, and displaying prior logon details; this surfaces anomalous or unauthorized use of network logon scripts at execution time, but only for the subset of observable logon events within the implemented scope rather than all possible script-based persistence.
- T1037.003prevents — A.8.5 mandates strong/MFA authentication, hardened log-on procedures (no cleartext, brute-force protection, session termination, alerts on failures), and appropriate strength for classified information; this directly stops adversaries from obtaining the credentials or admin access needed to assign or modify network logon scripts via AD/GPO, though some edge cases (e.g., already-compromised admin sessions or accessibility exemptions) remain.
- T1037.004detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or repeated failures, and separate-channel notifications of prior activity; these surface anomalous or unexpected root-level startup behavior on affected Unix-like platforms when it triggers a logon or session event, but the core technique (modifying an RC script that runs as root before most user sessions) has no mandatory instrumentation or detection surface in the clause.
- T1040detects — A.8.5 explicitly requires logging unsuccessful/successful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and sending notifications of prior failed attempts, which surfaces sniffing-derived credential theft when it triggers observable log-on anomalies; this is only a slice of the broad passive technique (e.g., non-auth traffic, config details, cloud mirroring, or network-device captures go unseen).
- T1040prevents — A.8.5 explicitly requires that passwords not be transmitted in clear text over networks (item j) and mandates strong/MFA authentication techniques whose material cannot be usefully captured by sniffing, directly stopping the technique's core goal of harvesting usable credentials; the named remainder is non-credential configuration data and already-encrypted sessions that can still be observed.
- T1047detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (including brute-force patterns), and monitoring for anomalous access factors such as unusual location/device/time; these surface some WMI abuse when it involves authentication or anomalous remote access patterns, but most native WMI execution (local COM/PowerShell, non-auth events) lies outside the control's authentication-focused scope.
- T1047prevents — A.8.5 mandates strong, MFA-based authentication (with failed-attempt limits, session termination, and alerts) proportionate to data classification; this directly stops unauthorized local/remote WMI use that relies on authenticated access to Windows components, though some local/privileged or non-interactive WMI abuse (e.g., via compromised processes) remains outside its reach.
- T1053detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (including brute-force or anomalous patterns), and separate-channel notification of prior log-ons/failures; these surface suspicious scheduled-task creation or remote scheduling that involves authentication, but only for the authentication slice of T1053, not the broader abuse of task-scheduling utilities, persistence, or masked execution on non-auth events.
- T1053prevents — A.8.5 mandates strong, MFA, brute-force protected, and context-aware authentication that must be satisfied before any scheduled task (local or remote) can be created or registered under a privileged context, directly stopping the technique for the bulk of enumerated platforms and vectors while leaving only the named remainder of already-authenticated sessions or exempted legacy accounts.
- T1053.002detects — A.8.5 requires logging of successful/unsuccessful log-on attempts plus raising security events/alerts on detected breaches of log-on controls, which surfaces anomalous use of at (especially for privilege escalation or breakout from restricted environments that involve authentication steps), but the control is silent on detecting the core technique of task scheduling itself or non-logon aspects of at abuse.
- T1053.002prevents — A.8.5 mandates strong, MFA, and hardened log-on procedures (including brute-force protection, session termination, and privilege-aware authentication strength) that stop unauthorized users from satisfying the admin/superuser or allowed-user prerequisites required to invoke `at` for scheduling or privilege-escalation tasks.
- T1053.003detects — A.8.5 requires logging of successful/unsuccessful log-on attempts plus raising security events on detected breaches of log-on controls, which surfaces anomalous cron job creation or execution tied to unauthorized access but does not broadly instrument cron abuse itself.
- T1053.005detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches of log-on controls, and displaying prior log-on details; these surface anomalous scheduled-task activity when it triggers authentication events, but the technique's core (task creation, hiding via registry edits, or non-interactive execution) is outside the log-on boundary so only a minority slice is detected.
- T1055detects — A.8.5 requires logging of log-on attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous patterns such as unusual location/device/time that can surface some process-injection activity when it triggers authentication flows, but the clause's scope is narrowly authentication-oriented and does not mandate host/process telemetry that would catch the bulk of T1055 implementations.
- T1055prevents — A.8.5 mandates MFA, strong auth, session termination, brute-force protection and logon hardening that can stop many credential-based or initial-access vectors commonly used to land and then perform process injection; this is a genuine but minority slice of the technique's full surface (which is mostly post-compromise, in-memory, and platform-specific abuse of legitimate APIs that authentication controls do not reach).
- T1055.001detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, and monitoring for anomalous access patterns (unusual location/device/time) that can surface DLL injection when it triggers authentication or session anomalies, but this is limited to specific observable side-effects rather than the core injection technique itself.
- T1055.001prevents — A.8.5's MFA, strong auth, session termination, brute-force protection and logon hardening raise the bar for initial access and privilege escalation that often precede or enable DLL injection, but do not stop an already-authenticated process from using VirtualAllocEx/WriteProcessMemory/CreateRemoteThread against another process.
- T1055.002detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, and monitoring for anomalous access patterns (unusual location/device/time) that can surface PE injection when it triggers authentication or session anomalies, but this is limited to specific observable side-effects rather than the injection technique itself.
- T1055.002prevents — A.8.5's MFA, strong auth, session termination, brute-force protection and logon hardening raise the bar for initial access and credential abuse that often precedes PE injection, but do not stop an already-authenticated process from using VirtualAllocEx/WriteProcessMemory/CreateRemoteThread inside a legitimate process.
- T1055.003detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and monitoring for anomalous access patterns (unusual location/device/time) that can surface thread-injection anomalies when they trigger authentication or session events; this covers most observable cases but leaves a bounded remainder for fully in-memory hijacks with no logon or anomaly trigger.
- T1055.003prevents — A.8.5 mandates strong/MFA authentication, logon hardening (brute-force protection, no cleartext, session termination, alerts on failures) and appropriate strength for classified information; this can prevent the initial access or credential theft that commonly enables process injection techniques such as thread hijacking, but does not stop an already-authenticated process from being hijacked via the listed Windows APIs.
- T1055.004detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or repeated failures, and monitoring for anomalous access patterns (unusual location/device/time) that can surface APC injection when it triggers authentication or privilege-related anomalies, but this is scoped only to logon events rather than the broader technique of code injection into live processes.
- T1055.004prevents — A.8.5 mandates strong/MFA authentication, failed-attempt limits, session termination, and log-on hardening that stop an adversary from obtaining the initial authenticated access or token needed to OpenThread/QueueUserAPC against a victim process; the named remainder is already-authenticated sessions or service accounts where the technique can still be used.
- T1055.009detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous access patterns (e.g. unusual location/device/time), which can surface some in-process injection activity when it triggers auth-related anomalies or events, but the control's scope is narrowly authentication flows rather than general process/memory behavior on Linux.
- T1055.014detects — A.8.5 requires logging of successful/unsuccessful log-on attempts plus raising security events/alerts on detected breaches of log-on controls, which can surface some anomalous process behavior tied to privilege-escalating injection; this is a minority slice of the Linux-specific VDSO technique that evades process-based defenses without touching authentication flows.
- T1055.015detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous access patterns (unusual location/device/time) that can surface ListPlanting when it triggers a log-on or session event, but the technique itself is a memory-injection shatter attack inside an already-authenticated process with no necessary log-on involvement.
- T1056detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, which surfaces many forms of input-capture (especially deceptive ones that trigger failed or anomalous logons); this is genuine detection but only a slice, as transparent hooking (T1056.004) often evades logon procedures entirely and the clause's scope is limited to authentication flows rather than all input mechanisms.
- T1056prevents — A.8.5 mandates strong/MFA authentication, anti-brute-force measures, secure log-on procedures, and no cleartext transmission of credentials, which directly stops most forms of credential input capture (including phishing, keyloggers on legitimate prompts, and network sniffing) from succeeding in obtaining usable credentials; the bounded remainder is transparent in-memory hooking (T1056.004) after the credential has already been legitimately provided to a trusted process.
- T1056.001detects — A.8.5 explicitly requires logging unsuccessful/successful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and other monitoring of log-on procedures that can surface keylogging in flight when it triggers those patterns, but this is scoped only to authentication flows rather than arbitrary keystroke capture methods (API hooks, drivers, hardware buffer reads) outside log-on.
- T1056.001prevents — A.8.5 mandates MFA, strong auth alternatives to passwords, no cleartext transmission/entry, session termination, brute-force protections, and logon-procedure hardening that stop most keylogging vectors from successfully capturing usable credentials; residual exposure remains for in-memory hooks on already-authenticated sessions or non-password factors.
- T1056.002detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and using MFA with contextual rules (unusual location/device/time) that surface anomalous credential prompts; this detects many GUI-input-capture attempts that trigger or mimic legitimate prompts, but leaves a named remainder of silent, non-logon, or non-anomalous mimics (e.g. fake installers or browser prompts without triggering rules or events).
- T1056.002prevents — A.8.5 mandates MFA, strong auth, anti-brute-force measures, secure log-on procedures, and session controls that stop most GUI credential prompts (including spoofed ones) from successfully harvesting usable credentials; the bounded remainder is legacy/single-factor paths or non-interactive injection that can still succeed.
- T1056.003detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on detected breaches or excessive failures, and separate-channel notification of prior activity, which surfaces anomalous credential-capture behavior on a portal; this is genuine but only a slice because the clause's scope is limited to log-on procedure instrumentation chosen by the implementer rather than mandating broad anomaly detection across all web portals or post-compromise admin-installed code.
- T1056.003prevents — A.8.5 mandates MFA, strong auth, brute-force protections, secure log-on procedures, no cleartext passwords, session termination, and alerts on suspicious logons; these directly stop credential capture on a legitimate portal from yielding usable access or being feasible at scale, though the control does not stop the initial page compromise itself.
- T1056.004detects — A.8.5 explicitly requires logging unsuccessful/successful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous access patterns (unusual location/device/time), which surfaces some in-process credential API hooking when it triggers observable log-on anomalies; this is only a slice because most hooking (especially non-logon, Linux LD_PRELOAD, or stealthy in-memory capture) evades these logon-focused controls.
- T1056.004prevents — A.8.5 mandates strong/multi-factor authentication techniques, log-on hardening (no cleartext, brute-force protection, session termination, separate-channel last-logon info) and rules-based additional factors that stop hooked credential APIs from yielding usable authentication material in the great majority of covered scenarios; the bounded remainder is the initial credential-capture step itself on exempted/legacy paths or before MFA is prompted.
- T1059prevents — A.8.5's MFA, brute-force protection, session termination, and log-on hardening raise the bar for initial access and credential abuse that often precedes interpreter execution, but do not stop an already-authenticated adversary (or malware) from abusing built-in interpreters such as PowerShell, Unix shells, or Python.
- T1059.002detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior activity; these surface anomalous authentication or script-driven access behaviors on macOS but only for the subset that triggers log-on controls, leaving the bulk of AppleScript execution (command-line osascript, Automator, in-memory NSAppleScript, non-auth SSH interaction, fake dialogs) outside the control's view.
- T1059.002prevents — A.8.5 mandates strong/multi-factor authentication, log-on hardening (no info leaks, brute-force protection, session termination, no cleartext passwords), and context-aware rules that stop unauthorized access to the macOS session or apps an AppleScript would need to abuse, preventing the technique from running; mostly because the control governs authentication strength rather than universal removal of all script interpreters or execution primitives.
- T1059.004detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous access patterns (unusual location/device/time) that can surface shell abuse via interactive shells (e.g. SSH lateral movement); this is genuine detection but only a slice of the broad technique (scripted/payload execution, non-interactive abuse, Busybox on embedded/ESXi) which mostly occurs without triggering logon controls.
- T1059.004prevents — A.8.5's MFA, brute-force protections, session termination, and strong auth requirements can stop some unauthorized shell access (especially interactive or post-lateral-movement), but the technique's core abuse of legitimate shell commands/scripts for execution, persistence, or C2 on already-authenticated sessions is unreached.
- T1059.007detects — A.8.5 requires logging of successful/unsuccessful log-on attempts plus raising security events/alerts on detected breaches of log-on controls, which surfaces some JavaScript-based execution when it triggers authentication flows (e.g. drive-by or script-launched logons), but the bulk of T1059.007 (standalone JS/JXA interpreters, in-memory execution, non-auth payloads) lies outside any log-on procedure.
- T1059.007prevents — A.8.5's MFA, brute-force protection, session termination, and log-on hardening raise the bar for initial access and credential abuse that often precedes or enables JS execution (e.g. via drive-by or downloaded payloads), but do not stop an already-authenticated user, scheduled task, or in-memory interpreter from running JS.
- T1059.008detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior activity; these surface anomalous or malicious CLI use on network devices (especially via SSH/telnet) but only for the authentication slice, not the broader technique of arbitrary command execution or configuration changes once inside.
- T1059.008prevents — A.8.5 mandates strong, MFA, brute-force protection, session termination, and non-cleartext auth that stop unauthorized CLI access on network devices (via SSH/console), preventing the adversary from reaching the interpreter; mostly because some access vectors (e.g. physical console, pre-compromised sessions) remain outside its direct reach.
- T1059.009detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior activity; these surface abuse of cloud API authentication surfaces (especially via shells, tokens, or sessions) when they trigger log-on controls, but only for the subset that intersects explicit log-on procedures rather than all API abuse post-authentication.
- T1059.009prevents — A.8.5 mandates strong, MFA-based authentication (with anti-brute-force, session termination, and credential-protection measures) proportionate to data classification; this directly stops adversaries from obtaining the credentials or session tokens needed to abuse cloud APIs, though some edge cases (e.g. compromised MFA, legacy bypasses, or stolen tokens) remain as named residue.
- T1059.012prevents — A.8.5 mandates strong/MFA authentication, hardened log-on procedures (no cleartext, brute-force protection, session termination, alerts), and appropriate strength for classified information; this stops many unauthorized logons that would let an adversary reach and abuse the hypervisor CLI, but leaves a bounded remainder (e.g. already-authenticated admin sessions, stolen credentials, or non-interactive hypervisor service accounts on ESXi).
- T1059.013prevents — A.8.5's MFA, strong auth, session termination, brute-force protection and logon-procedure rules can stop unauthorized use of the Docker/K8s CLI or API when that access requires authenticated identity; this is a genuine but minority slice of the technique, which also covers already-authenticated sessions, local container daemons, misconfigured RBAC, and direct API abuse by compromised service accounts.
- T1069.003prevents — A.8.5 mandates strong, MFA, and hardened log-on procedures (brute-force protection, no cleartext, session termination, alerts) that stop an adversary who has obtained initial credentials from successfully authenticating to run the discovery commands that enumerate cloud groups and ACLs.
- T1071.004detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches of log-on controls, and (implicitly via MFA/strong auth) anomalous access patterns such as unusual location/device/time; these surface some DNS-tunneling C2 when it rides authentication flows or triggers anomaly rules, but the technique's core (pre-auth DNS blending, infrequent beacons, non-auth traffic) sits outside authentication's scope.
- T1072detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and separate-channel notification of prior activity, which can surface anomalous admin logins to deployment tools but only for the authentication slice of the technique, not the subsequent abuse or non-auth access vectors.
- T1072prevents — A.8.5 mandates strong, MFA-backed authentication (with anti-brute-force, session termination, and logon hardening) proportionate to data classification; this directly stops the administrative or domain credentials required to log into and abuse deployment tools such as SCCM, Intune, or AWS Systems Manager, though local-credential or already-compromised sessions remain a bounded remainder.
- T1078prevents — Mandating MFA and non-password authenticators raises the bar for attackers who have obtained valid credentials but still need an additional factor.
- T1078detects — A.8.5 explicitly requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failures, and notifying users/admins of anomalous prior failed attempts, which surfaces abuse of valid accounts; this is only a slice because the control is scoped to authentication events at logon boundaries rather than all post-authentication abuse, pivoting, or inactive-account usage across the technique's broad platform and tactic range.
- T1078.001detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and notifying users/admins of prior unsuccessful attempts, which surfaces abuse of default accounts when they are used for logon; this is only a slice of the technique because default-account abuse can also occur via non-logon vectors such as stolen keys, post-setup integration accounts, or credential use without triggering a monitored log-on event.
- T1078.001prevents — A.8.5 mandates strong, MFA, brute-force protection, session termination, and non-default-strength authentication that stops abuse of unchanged preset/default accounts in the great majority of cases; the bounded remainder is the subset of factory defaults that are exempted, legacy, or integrated post-setup in ways the clause does not reach.
- T1078.002detects — A.8.5 explicitly requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failures, and notifying on prior failed attempts, which surfaces abuse of obtained domain credentials when they are used; this is only a slice of the technique (use-phase detection) and does not address credential acquisition itself (e.g. dumping or reuse before use).
- T1078.002prevents — A.8.5 mandates strong/multi-factor authentication, failed-attempt protections, session termination, and non-cleartext handling that stop many credential-abuse paths (guessing, reuse, sniffing, brute-force) against domain accounts; the bounded remainder is already-compromised credentials (e.g. via dumping) that can still be presented successfully.
- T1078.003detects — A.8.5 explicitly requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior logon details, which surfaces abuse of local account credentials; this is only a slice because the clause is scoped to authentication events at logon and does not broadly instrument credential dumping, reuse across systems, or non-logon abuse vectors for local accounts.
- T1078.003prevents — A.8.5 mandates strong, MFA, brute-force protection, session termination, and logon hardening that stops many (but not all) ways of obtaining and abusing local account credentials, especially password-based ones; the named remainder is non-password local accounts, misconfigurations, or already-compromised credentials.
- T1078.004detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and notifying users/admins of prior activity, which surfaces adversary use of valid cloud accounts (e.g. brute-force or anomalous logons) but only for the authentication slice, not the broader technique's persistence, privilege escalation, lateral movement or misconfiguration aspects.
- T1078.004prevents — A.8.5 directly mandates MFA, brute-force protections, strong non-password methods, session termination, and log-on hardening that stop the credential-theft and brute-force vectors named in T1078.004; the bounded remainder is post-compromise use of already-valid federated or misconfigured high-privilege accounts that the control does not reach.
- T1087prevents — A.8.5's MFA, brute-force protections, log-on procedure hardening and session termination raise the bar for follow-on brute-force, phishing and takeover uses of discovered accounts, but do nothing to stop the initial enumeration itself via commands, APIs or file searches.
- T1087.003detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches (e.g. repeated failures), and separate-channel notifications of prior activity; this surfaces anomalous authenticated sessions that could be reconnaissance for T1087.003 but does not broadly instrument the post-auth enumeration itself.
- T1087.003prevents — A.8.5 mandates strong, MFA, brute-force protection, session termination and logon-procedure hardening that stop an adversary obtaining the authenticated session required to run Get-GlobalAddressList or equivalent directory queries; the bounded remainder is already-authenticated sessions or non-password vectors that still allow the technique.
- T1087.004prevents — A.8.5 mandates strong, MFA-based authentication (with brute-force protection, session termination, and log-on hardening) proportionate to data classification; this directly stops adversaries from obtaining the authenticated access required to run any of the listed discovery commands against cloud accounts.
- T1098detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and notifying on prior failed attempts, which surfaces many forms of account manipulation such as brute-force credential changes or anomalous logons; this is only a slice because the control is scoped to authentication events and does not broadly detect post-auth manipulation of permissions, groups, or credential lifetime policies once inside a valid session.
- T1098prevents — A.8.5 mandates strong/multi-factor authentication, failed-attempt protections, session termination, and log-on hardening that stop most forms of credential or permission manipulation from being usable or sustainable, but the technique can still succeed against exempted accounts, legacy paths, or post-compromise permission-group changes that do not rely on authentication.
- T1098.001detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and notifying on prior unsuccessful attempts, which surfaces many (but not all) credential-addition actions performed via console/CLI that touch authentication flows.
- T1098.001prevents — A.8.5 mandates MFA, alternative strong auth methods, brute-force protections, session termination, and log-on hardening that stop most credential-addition paths (especially app passwords, console logins, and weak/legacy auth bypasses) when the technique relies on authentication; named remainder is direct API abuse by already-privileged identities that does not traverse a protected log-on.
- T1098.002detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and notifying on recent activity; this surfaces anomalous permission grants when they occur via an authenticated session (the dominant vector for T1098.002), but the control is silent on non-logon vectors such as direct API/admin-console delegation or folder-permission changes without triggering a log-on event.
- T1098.002prevents — A.8.5 mandates strong/multi-factor authentication, log-on hardening (brute-force protection, no cleartext passwords, session termination, alerts on failed attempts) and strength proportionate to data classification, which directly stops adversaries from authenticating as the mailbox owner to then run Add-MailboxPermission or equivalent delegation commands; the bounded remainder is post-compromise insider or already-authenticated sessions where the technique can still be issued without re-authenticating.
- T1098.003detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events on potential breaches (e.g. repeated failures), and notifying on anomalous logon patterns such as unusual location/device/time; these surface the account/role modification when it triggers an authentication event, but most of the technique (API-driven IAM policy updates or role grants on already-compromised accounts with no new logon) sits outside authentication flows.
- T1098.003prevents — A.8.5 mandates strong/multi-factor authentication, failed-attempt protections, session termination, and log-on hardening that stop an adversary from successfully authenticating to perform the AttachUserPolicy/CreatePolicyVersion/etc. actions that realize T1098.003; the bounded remainder is already-authenticated sessions or external accounts that bypass the victim tenant's auth surface.
- T1098.004detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and displaying prior log-on details; these surface anomalous SSH key usage at authentication time on covered platforms, but the technique's core (file modification via shell, cloud API, or config edit) occurs outside the log-on procedure itself and is unseen by these controls on many platforms.
- T1098.004prevents — A.8.5 requires choosing suitable/strong authentication techniques (MFA, non-password methods, brute-force protections, secure log-on procedures) proportionate to information classification; this directly constrains or blocks many SSH authorized_keys abuse vectors (e.g. by mandating MFA or alternative factors that stop key-only logins, disabling weak configs, and protecting against unauthorized key additions via procedural and technical means), though a bounded remainder exists for implementations that still permit key-based auth under the clause's 'appropriate strength' allowance.
- T1098.005detects — A.8.5 explicitly requires logging successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failures, and notifying on prior failed attempts, which surfaces anomalous device registration (especially self-enrollment or post-compromise MFA bypass) as detectable events; partial because this is limited to logon-time signals and does not broadly instrument device enrollment, Intune/Entra registration, or conditional-access bypass outside that narrow scope.
- T1098.005prevents — A.8.5 mandates MFA (with strength proportionate to data classification), alternative factors, brute-force protections, session termination, and rules-based additional factors for unusual access patterns — directly blocking the credential-compromise-to-device-enrollment path that lets an adversary bypass initial MFA or conditional access policies in the bulk of described scenarios.
- T1098.006detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior activity; these surface anomalous permission/role changes when they involve authentication events or patterns, but the core of T1098.006 (creating bindings or editing ABAC policies) is a post-auth privileged action with no mandated detection in the clause.
- T1098.006prevents — A.8.5 mandates strong, MFA-based authentication (with brute-force protection, session termination, and alerts) proportionate to information classification; this directly stops an adversary from obtaining the initial credentials or session needed to perform the privileged RoleBinding/ABAC modification that T1098.006 requires.
- T1098.007detects — A.8.5 requires logging of successful/unsuccessful logon attempts plus raising security events on detected breaches of log-on controls, which surfaces anomalous group-addition activity when it triggers a subsequent privileged logon (e.g. new RDP or sudo use); this is genuine detection of the technique's downstream effect but only a minority slice of the group-addition act itself, which can be performed silently without any logon.
- T1110prevents — Locking accounts or requiring resets after repeated failed attempts, plus CAPTCHA, directly limits the number of guesses an attacker can make before being blocked.
- T1110detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising a security event/alert on potential breach (e.g. after failed attempts), which surfaces brute-force activity in flight or post-attempt.
- T1110responds — A.8.5 explicitly requires raising a security event, sending alerts to users/admins on excessive failed attempts, logging successes/failures, and using MFA/conditional rules that act once brute-force guessing is underway, which is the core of `responds` (containment/eradication in flight); the remainder is offline hashing attacks and fully successful logins before response triggers.
- T1110.001prevents — The same brute-force protections and account lockouts reduce the feasibility of automated password guessing against individual accounts.
- T1110.001detects — A.8.5 explicitly requires logging of unsuccessful/successful log-on attempts, raising security events/alerts on potential breaches (e.g. after failed attempts), and displaying prior failed log-ons, which surfaces password guessing in flight or after the fact across the technique's core login vectors.
- T1110.001responds — A.8.5 explicitly requires raising a security event and sending alerts on detected breach of log-on controls (including brute-force guessing attempts), which is the core act of `responds` once the technique is underway; the remainder is that the clause does not itself perform containment or eradication.
- T1110.002detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and other observable indicators that surface password-cracking attempts in flight or post-facto on the monitored estate.
- T1110.002prevents — A.8.5 mandates MFA, strong auth alternatives to passwords, brute-force protections (rate limiting, CAPTCHA, account lockout), no cleartext transmission/storage, session termination, and logon procedure hardening that directly stop offline cracking from yielding usable access or online guessing from succeeding.
- T1110.003prevents — Rate-limiting and lockout mechanisms blunt password-spraying campaigns that rely on many rapid, low-and-slow attempts across numerous accounts.
- T1110.003detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising a security event/alert on potential breaches or thresholds (e.g. repeated failures), and notifying on prior failures, which surfaces password spraying attempts even when throttled or using protocols like LDAP/Kerberos.
- T1110.003responds — A.8.5 explicitly requires raising a security event and sending alerts on detected potential or successful breach of log-on controls (including brute-force / spraying patterns via failed-attempt thresholds), which is the core act of `responds` once the technique is underway.
- T1110.004detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. after repeated failures), and notifying users/admins of prior failures on successful log-on, which surfaces credential-stuffing attempts in flight or immediately after.
- T1110.004prevents — A.8.5 mandates MFA, brute-force protections (rate limiting, lockouts, CAPTCHA), no clear-text transmission, session termination, and strength proportionate to data classification; these directly stop credential-stuffing attacks that rely on password-only reuse across services, with the bounded remainder being MFA-exempted accounts, legacy protocols, or static service secrets explicitly allowed by the clause.
- T1110.004responds — A.8.5 explicitly requires raising a security event and sending alerts on detected potential or successful breach of log-on controls (including brute-force or repeated failures that credential stuffing produces), which is the core of `responds` once the technique is underway; the remainder is that it does not itself perform containment/eradication.
- T1111detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and displaying prior unsuccessful attempts, which surfaces interception attempts against MFA mechanisms (e.g. keyloggers, token capture, or anomalous out-of-band code use) but only for a slice of the technique's vectors and platforms.
- T1111prevents — A.8.5 directly mandates MFA (and stronger alternatives to passwords) with strength proportionate to information classification, plus explicit protections against brute-force, clear-text transmission, session hijacking, and log-on information leakage that stop most described interception vectors before they succeed; the bounded remainder is post-compromise device-level keyloggers and out-of-band channel compromises that the clause does not reach.
- T1114.002detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or repeated failures, and separate-channel notifications of prior activity, which can surface anomalous credential use against Exchange/Office 365 but does not broadly instrument or detect the subsequent email collection activity itself
- T1114.002prevents — A.8.5 mandates strong, MFA, brute-force protection, session termination and credential hygiene that stop an adversary from successfully using stolen or guessed credentials against Exchange/Office 365, preventing the technique from succeeding; the bounded remainder is legitimate credential use or token theft after successful MFA.
- T1114.003detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on detected breaches or excessive failures, and separate-channel notification of prior activity; these surface anomalous credential use that can precede or accompany rule creation, but do not address rule creation itself, hidden MAPI rules, transport rules, or post-auth forwarding activity.
- T1114.003prevents — A.8.5 mandates strong, MFA-backed authentication (with brute-force protection, session termination, and log-on hardening) that stops an adversary without valid credentials from reaching the email client or admin interface where forwarding rules are created; the named remainder is the case of already-compromised credentials, which the control explicitly acknowledges as a boundary.
- T1123detects — A.8.5 requires logging of successful/unsuccessful logons plus raising security events/alerts on detected breaches of log-on controls, which surfaces anomalous authentication tied to malware using audio APIs; this is a genuine but minority slice of T1123 (most audio capture uses no new logon and lives in runtime/process behavior outside A.8.5's scope).
- T1127.001detects — A.8.5 requires logging of successful/unsuccessful logons plus raising security events on detected breaches or brute-force patterns, which can surface anomalous use of MSBuild.exe as a living-off-the-land binary; this is genuine detection of the technique in flight but only a minority slice, as the control is scoped to authentication flows and does not mandate host/process/behavior monitoring that would catch arbitrary MSBuild inline task execution.
- T1127.002detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, and separate-channel notification of prior logon details; these surface anomalous or suspicious authentication activity that can accompany ClickOnce abuse vectors (e.g. user-driven execution or startup persistence), but the clause is silent on runtime process monitoring, child-process anomalies, or non-authentication indicators of the technique itself.
- T1127.002prevents — A.8.5 mandates strong/MFA authentication, log-on hardening (no cleartext, brute-force protection, session termination, alerts on failures) and appropriate strength for classified information; this directly stops the user-execution vector that supplies the malicious ClickOnce payload in the large majority of described abuse paths, with only the post-auth lateral/persistence slices (startup folder, rundll32 proxy) as bounded remainder.
- T1133detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and notifying users/admins of anomalous log-on details (prior success time, failed attempts since last success), which surfaces many T1133 uses that rely on credentialed remote service access while leaving unauthenticated exposures, Tor hidden services, and non-logon vectors undetected.
- T1133prevents — A.8.5 mandates strong, MFA, brute-force protection, session termination, and non-cleartext auth for remote services (VPNs, RDP, etc.), stopping most credential-based and weak-auth T1133 vectors; remainder is exposed unauthenticated services and post-compromise persistence like Tor hidden services.
- T1134detects — A.8.5 requires logging of successful/unsuccessful log-on attempts plus raising security events/alerts on detected breaches of log-on controls, which can surface anomalous token-based authentication or impersonation after the fact; however, the control is scoped only to log-on procedures and does not broadly instrument process token manipulation, API calls, or runtime security context changes.
- T1134.001detects — A.8.5 explicitly requires logging of successful/unsuccessful logon attempts, raising security events/alerts on potential breaches or repeated failures, and separate-channel notification of prior logons and failed attempts, which can surface anomalous token-impersonation behavior tied to logon sessions on Windows; this is only a slice because the control is scoped to authentication/logon procedures and does not mandate host/process monitoring for in-memory token duplication or thread impersonation after initial access.
- T1134.001prevents — A.8.5 mandates strong/MFA authentication, logon hardening (no cleartext, brute-force protection, session termination, alerts on failures) and appropriate strength for classified information, which stops many token-theft paths at initial access or lateral movement; it does not address in-session token duplication or impersonation APIs once a process is already authenticated on Windows.
- T1134.002detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or repeated failures, and monitoring for anomalous access patterns (unusual location/device/time), which can surface T1134.002 when it triggers a new process under an impersonated token; this is only a slice because the clause is scoped to authentication events rather than process-creation or token-use telemetry.
- T1134.002prevents — A.8.5 mandates strong/MFA authentication, logon hardening (brute-force protection, no cleartext, session termination, alerts on failures) and appropriate strength for classified information; this constrains many paths to obtaining/using a foreign token for CreateProcessWithTokenW but leaves residual cases (e.g. already-compromised admin sessions, pass-the-token after initial access, or non-interactive service contexts) untouched.
- T1134.003detects — A.8.5 explicitly requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches (e.g. repeated failures), and separate-channel notification of prior logon details, which surfaces anomalous token-creation activity when it triggers those observables; this is only a slice because the clause scopes detection to logon procedures rather than the broader post-auth token manipulation or impersonation mechanics described.
- T1134.003prevents — A.8.5 mandates strong/MFA authentication, protected logon procedures, brute-force defenses, session termination, and non-cleartext credential handling, which stops adversaries from obtaining the valid username+password needed to call LogonUser and create an impersonation token on Windows.
- T1134.005detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, and separate-channel notification of prior logon details; these surface anomalous privilege-escalation or lateral-movement activity that can result from SID-History injection, but the control is scoped to authentication events rather than directly monitoring AD attribute manipulation or token contents.
- T1136detects — A.8.5 explicitly requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failures, and notifying on anomalies like unusual access patterns, which surfaces account-creation activity when it triggers those observables, but only a minority slice of T1136 (e.g. post-creation use or noisy local creation) is caught versus stealthy cloud/service-specific account creation that evades logon-focused detection.
- T1136prevents — A.8.5 mandates strong, MFA-backed authentication (with brute-force protection, session termination, and log-on hardening) that stops an adversary-created account from being usable for access or persistence, even though the account-creation act itself is not blocked.
- T1136.003prevents — A.8.5 mandates strong, MFA-backed authentication (with brute-force protection, session termination, and alerts) proportionate to data classification; this directly stops an adversary-created cloud account from being usable for access or persistence in most cases, though low-privilege or exempted service accounts remain a bounded remainder.
- T1137detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or repeated failures, and monitoring for anomalous patterns (unusual location/device/time) that can surface abuse of Office startup mechanisms such as add-ins or rules when they trigger authentication events; this is a genuine but minority slice of the technique (most T1137 abuse is silent at startup and does not involve logon).
- T1137prevents — A.8.5 mandates strong/multi-factor authentication, failed-attempt protections, session termination, and log-on hardening that stop an adversary from authenticating to abuse Office startup mechanisms (e.g. rules, add-ins, or macros) for persistence; the bounded remainder is local unauthenticated Office features or already-authenticated sessions.
- T1137.001detects — A.8.5 requires logging of successful/unsuccessful logons plus raising security events/alerts on detected breaches of log-on controls, which surfaces anomalous macro-enabled template loading at application startup on the monitored endpoint; this is a genuine but minority slice of the full technique (registry hijacks, remote templates, and macro-enablement policy bypasses often occur without triggering a logon event).
- T1137.001prevents — A.8.5's MFA, strong auth, log-on hardening, brute-force protection, session termination and credential transmission rules constrain the macro-enabled template abuse vector when it depends on an authenticated log-on or credential compromise, but the technique can still be realized post-compromise via local template modification or registry hijack without triggering those controls.
- T1137.002detects — A.8.5 requires logging of successful/unsuccessful log-on attempts plus raising security events on detected breaches of log-on controls; this can surface anomalous Office-startup behavior tied to the persistence technique on Windows/Office platforms, but only as a minority slice (most Office Test abuse is not expressed as a log-on event).
- T1137.003detects — A.8.5 requires logging of successful/unsuccessful logons plus raising security events/alerts on detected breach attempts, which surfaces anomalous logon or form-loading activity tied to the technique on Windows/Outlook but does not broadly instrument form registration or email-triggered code execution itself.
- T1137.003prevents — A.8.5's MFA, strong auth, logon hardening (brute-force protection, session termination, no cleartext creds) and anomaly-triggered extra factors can stop the initial compromise or credential abuse needed to plant the malicious Outlook form, but do not block the technique once the mailbox is already compromised or when the form auto-executes on crafted mail.
- T1137.004detects — A.8.5 requires logging of successful/unsuccessful logons plus raising security events/alerts on detected breaches of log-on controls, which can surface anomalous Outlook startup or folder loads tied to the technique; this is a genuine but minority slice of the persistence (most executions are not tied to a new logon event).
- T1137.004prevents — A.8.5 requires strong/MFA authentication, log-on hardening (brute-force protection, no cleartext, session termination, alerts on failures) and appropriate strength for classified information; this stops many vectors for adding a malicious Outlook Home Page but leaves open the bounded remainder of already-authenticated sessions, compromised credentials, or non-authentication paths such as malicious add-ins or direct registry/mailbox manipulation post-compromise.
- T1137.005detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior unsuccessful attempts; this surfaces anomalous rule-triggered execution when it manifests as suspicious log-on or email-driven behavior, but only for the subset of T1137.005 realizations that cross the log-on boundary rather than purely mailbox-rule persistence.
- T1137.005prevents — A.8.5 mandates strong/multi-factor authentication, failed-attempt limits, session termination, and log-on hardening that stop an adversary from authenticating to add or trigger malicious Outlook rules on the mailbox.
- T1137.006detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or repeated failures, and monitoring for anomalous access patterns (unusual location/device/time) that can surface add-in-driven persistence when it triggers Office startup or authentication flows; this is a genuine but minority slice of the technique (most add-in abuse is silent at load time and does not involve logon events).
- T1137.006prevents — A.8.5 mandates strong/MFA authentication, secure log-on procedures (including brute-force protection, session termination, and no cleartext creds), and strength proportionate to data classification; this constrains add-in-based persistence when the add-in requires Office launch + user auth (especially from unusual contexts or for critical systems), but leaves a large remainder where add-ins auto-execute on app start without triggering auth, on non-auth paths, or via already-authenticated sessions.
- T1176prevents — A.8.5's MFA, strong auth, log-on hardening, session termination and brute-force protections can stop an adversary from installing or activating a malicious extension when that step requires authenticated access to a marketplace, IDE, or endpoint, but the technique's dominant vectors (social engineering, compromised marketplaces, manual side-loading, and abuse of already-installed benign extensions) lie outside authentication strength.
- T1176.001detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches, and monitoring for anomalous access patterns (unusual location/device/time), which can surface suspicious extension-driven credential theft or anomalous browser behavior post-install; this is a genuine but minority slice of the technique's full scope (silent file modification, app-store evasion, background persistence, and stealth modifications).
- T1176.001prevents — A.8.5 mandates strong/MFA authentication, secure log-on procedures, brute-force protection, and session termination that can block credential theft or unauthorized extension-driven access in some scenarios, but does not stop silent file-based installation, social engineering, or post-compromise persistence of malicious browser extensions.
- T1185detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior activity; these surface anomalous or hijacked session use after the fact, but only for the subset of T1185 that manifests at authentication boundaries rather than via injection, proxying, or in-browser pivoting that bypasses log-on.
- T1185prevents — A.8.5 mandates MFA, strong auth, session termination, and logon protections that stop many hijacking vectors (e.g. stolen cookies/sessions, brute-force, cleartext creds, or unauthenticated pivots), but leaves residual cases such as post-auth injection into an already-authenticated high-integrity browser process that inherits valid sessions/certificates.
- T1187detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, which surfaces forced-authentication attempts that trigger observable log-on activity (e.g. to external SMB/WebDAV resources), but this is limited to the log-on surface and does not broadly instrument the technique's other vectors like EFSRPC or file icon rendering.
- T1187prevents — A.8.5 mandates strong/MFA authentication, log-on hardening (no cleartext passwords, brute-force protection, session termination, separate-channel last-logon info) and appropriate technique strength; these stop most forced-authentication flows (SMB/WebDAV hash capture, NTLM relay) from succeeding or being useful, with a bounded remainder for legacy protocols, exempted accounts, or pre-auth interception vectors.
- T1189detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, and separate-channel notification of prior activity; these surface anomalous authentication events that can result from a successful drive-by but do not broadly instrument the browser exploit delivery, scripting, or initial code execution steps of T1189.
- T1189prevents — A.8.5's MFA, strong auth, session termination, brute-force protections, and logon-procedure hardening can stop credential-theft or session-abuse vectors that sometimes follow initial drive-by code execution, but the core browser exploit and initial code execution in T1189 occur before any authentication step and are untouched by the control.
- T1190prevents — A.8.5 mandates strong/MFA authentication, logon protections (brute-force limits, no cleartext, session termination, etc.) that stop many authentication-bypass or weak-credential exploits against public-facing apps/services (e.g. SSH, web auth flaws, weak IAM), but leaves the bulk of T1190's software bugs, misconfigurations, and non-auth vulnerabilities (SQLi, RCE, container escapes, edge-device flaws) untouched.
- T1199detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events on potential breaches (e.g. brute-force thresholds), and alerting on anomalies like unusual location/device/time, which surfaces some trusted-relationship abuse that manifests as anomalous authentication but does not broadly detect supply-chain compromise of the third-party account itself or delegated admin offers.
- T1199prevents — A.8.5 requires strong, MFA-backed authentication (with anti-brute-force, session termination, and no-cleartext rules) for any entity granted access, which stops many third-party credential compromises that would otherwise enable T1199; it leaves a bounded remainder where the trusted relationship itself is the vector (e.g. already-approved delegated admin offers or supply-chain compromise of the provider before authentication occurs).
- T1201prevents — A.8.5 requires strong MFA, brute-force protections (lockouts, CAPTCHA, alerts), session termination, and no cleartext passwords, which directly stops most discovery techniques (CLI queries, APIs, sniffing) by enforcing policy that either blocks the access path or renders the gathered policy useless for subsequent attacks.
- T1204detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failures, and separate-channel notifications of prior activity, which can surface anomalous user actions tied to execution (e.g. enabling RATs or running unexpected payloads) but only for the narrow subset involving authentication or session events, not the dominant social-engineering or file-execution vectors of T1204.
- T1204prevents — A.8.5's MFA, strong auth, session termination, brute-force protection, and logon procedure hardening raise the bar for credential theft or session hijacking that often precedes or enables social-engineering tricks (e.g. stolen cookies, RAT enablement, coerced execution), but the technique itself is user action after phishing/social engineering and is not stopped by authentication controls.
- T1204.001detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, and separate-channel notifications of prior activity; these surface anomalous user actions that can indicate a malicious link was clicked, but only for the narrow subset of cases that trigger an actual authentication flow rather than silent execution or file download.
- T1204.001prevents — A.8.5 mandates MFA, strong auth, session termination, brute-force protection, and logon design that blocks unauthorized access; this directly stops the authenticated user session (or the social-engineering-induced click) that T1204.001 requires to reach execution, with the bounded remainder being pre-authentication phishing clicks on air-gapped or unauthenticated links.
- T1204.002detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, and separate-channel notification of prior logon history; these surface anomalous user file-execution behavior when it triggers a logon or authentication event, but the core of T1204.002 (social engineering to open a malicious file) has no authentication step and is invisible to the control.
- T1204.004detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior failed attempts; this surfaces the social-engineering vector when it triggers a log-on or command execution that matches those patterns, but the core technique (user copy-paste of obfuscated commands from fake errors/CAPTCHAs outside an explicit log-on flow) is only partially covered by those specific detection points.
- T1205.001detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and monitoring for anomalous access patterns (unusual location/device/time), which can surface port-knocking sequences that rely on connection attempts; however, the control is scoped to authentication/log-on procedures rather than arbitrary closed-port probes or raw-socket sniffing, leaving most of the technique outside its view.
- T1210detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior logons — all of which can surface exploitation attempts against remote services that involve authentication or log-on activity (e.g. RDP, SMB), but this is only a slice of the technique whose dominant vector is direct vulnerability exploitation without necessarily triggering log-on controls.
- T1212detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on detected breaches or brute-force patterns, and displaying prior failed attempts; this surfaces some exploitation-for-credential-access techniques (especially replay or anomalous log-on) but does not broadly instrument for vulnerability exploitation, token forging, or credential dumping in non-auth flows.
- T1212prevents — A.8.5 mandates strong, multi-factor, replay-resistant authentication techniques with explicit protections against brute-force, cleartext transmission, session hijacking and improper validation — directly closing the authentication bypass and replay vectors named in T1212; the bounded remainder is memory-corruption or logic flaws inside the credential store or token issuer itself that lie outside the authentication interface.
- T1213prevents — A.8.5 mandates strong, MFA-backed authentication (with anti-brute-force, session termination, and no-cleartext measures) that stops unauthenticated or weakly-authenticated access to repositories, directly closing the 'public/unauthenticated' and 'overly-broad' access vectors named in the T1213 description; mostly because the technique can still succeed via a legitimately authenticated session or stolen credential.
- T1213.001prevents — A.8.5 mandates strong, MFA-backed authentication (with brute-force protection, session termination, and no cleartext exposure) proportionate to data classification; this directly stops the adversary from reaching and mining the Confluence repository when it holds sensitive information, though the control's effect is bounded by the remainder of public/unauthenticated Confluence instances or weak implementations that still allow access.
- T1213.002detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, and separate-channel notifications of prior activity, which can surface anomalous SharePoint access patterns that indicate mining is underway.
- T1213.002prevents — A.8.5 mandates MFA, strong auth, brute-force protection, session termination, and log-on hardening that stop an adversary from authenticating to reach and mine the SharePoint repository; the bounded remainder is already-authenticated sessions or non-auth protections such as SharePoint permissions.
- T1213.003prevents — A.8.5 mandates strong, MFA-backed authentication (with anti-brute-force, session termination, and log-on hardening) for systems and services including private code repositories; this stops the adversary from gaining the initial access needed to collect from them, with only a bounded remainder (e.g., compromised credentials or MFA-exempt service accounts) left unaddressed.
- T1213.004prevents — A.8.5's strong/multi-factor auth, failed-attempt blocking, session termination, and log-on hardening directly stop many unauthorized accesses that would let an adversary reach and mine the CRM; the technique's premise is already having some foothold, so only a slice of access paths is prevented.
- T1213.006prevents — A.8.5's strong/multi-factor auth, brute-force protections, MFA on critical systems, and logon hardening directly stop many database access attempts that rely on stolen/weak credentials or guessing, but the technique also covers direct exploitation of misconfigured DBs, exposed services, or already-compromised sessions that do not require re-authentication.
- T1216detects — A.8.5 requires logging of successful/unsuccessful logon attempts plus raising security events/alerts on potential breaches of log-on controls, which can surface anomalous use of signed scripts for proxy execution when it triggers those logon-related patterns, but the clause's scope is narrowly authentication-oriented and does not broadly instrument process/script execution, LOLBAS usage, or AppLocker bypasses.
- T1216prevents — A.8.5 mandates strong/multi-factor authentication, protected logon procedures, brute-force defenses, and session termination that can block many credential-theft or unauthorized-execution vectors used to launch T1216 proxies, but leaves the core technique (abusing already-authenticated, signed Microsoft scripts that bypass application control) reachable on a live session.
- T1216.002detects — A.8.5 requires logging of successful/unsuccessful log-on attempts plus raising security events/alerts on detected breaches of log-on controls; this can surface anomalous use of SyncAppvPublishingServer.vbs as a signed proxy for PowerShell, but the clause's scope is limited to authentication events and does not broadly instrument script execution or LOLBin abuse.
- T1218.003detects — A.8.5 requires logging of successful/unsuccessful log-on attempts plus raising security events/alerts on detected breaches of log-on controls, which can surface anomalous use of CMSTP.exe for proxy execution or UAC bypass when it involves authentication flows, but the control's scope is narrowly authentication-oriented and does not broadly instrument process execution, INF parsing, or COM/scriptlet abuse.
- T1218.004detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous access patterns (unusual location/device/time) that can surface InstallUtil proxy execution when it triggers authentication or log-on flows; this is a genuine but minority slice of the technique's possible executions (many of which are non-interactive, do not involve log-on, or evade the logon-specific mechanisms).
- T1218.004prevents — A.8.5 mandates strong/MFA authentication, hardened logon procedures (no cleartext, brute-force protection, session termination, alerts on failures) and appropriate strength for classified information; this directly prevents the initial authenticated access or credential compromise needed to reach and run InstallUtil for proxy execution or AppControl bypass on Windows.
- T1218.005detects — A.8.5 requires logging of successful/unsuccessful logon attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous patterns such as unusual locations/devices/times; these surface some mshta.exe abuse when it triggers logon-like or anomalous execution events, but the bulk of the technique (proxy script/HTA execution bypassing browser controls without necessarily involving authentication) lies outside the clause's authentication-focused scope.
- T1218.005prevents — A.8.5's MFA, strong auth, logon hardening, session termination and brute-force protections can stop unauthorized invocation of mshta.exe when it requires authenticated access or occurs from unusual context, but the technique is commonly used in unauthenticated initial access, script execution or by already-authenticated malware so only a slice is prevented.
- T1218.007detects — A.8.5 requires logging of successful/unsuccessful logon attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous access patterns (unusual location/device/time) that can surface msiexec.exe abuse when it involves authentication, elevation, or anomalous execution; this is a genuine but minority slice of the technique (most msiexec abuse is not authentication-centric).
- T1218.008detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous access patterns (unusual location/device/time) that can surface suspicious use of signed binaries like odbcconf.exe for proxy execution, but this is limited to logon-related or rule-triggered anomalies rather than directly targeting the technique's DLL proxying or application-control bypass.
- T1218.008prevents — A.8.5 requires strong/MFA authentication, hardened logon procedures, brute-force protection, session termination, and non-cleartext credential handling; these block many credential-theft or unauthorized-execution paths that could lead to abusing a signed binary like odbcconf.exe, but do not stop an already-authenticated process, a compromised admin session, or direct abuse of a living-off-the-land binary that requires no additional authentication.
- T1218.010prevents — A.8.5's strong/multi-factor auth, logon hardening, brute-force protection, session termination and MFA rules can stop many regsvr32 abuse paths that rely on stolen credentials or interactive logons, but the technique's core (signed binary proxying DLL/COM/scriptlet execution under already-authenticated user context) is unaffected by authentication strength.
- T1218.012detects — A.8.5 requires logging of successful/unsuccessful logon attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous access patterns (unusual location/device/time) that could surface suspicious verclsid.exe proxy execution, but this is limited to authentication events and does not broadly instrument process execution, COM abuse, or LOLBin activity.
- T1218.013detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, and monitoring for anomalous access patterns (unusual location/device/time) that can surface mavinject.exe abuse when it triggers authentication or session anomalies, but this is limited to specific observable slices rather than the core injection technique itself.
- T1218.014detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous access patterns (unusual location/device/time) that can surface MMC abuse when it triggers authentication or log-on flows, but this is only a slice of the technique's execution paths (e.g. non-interactive CLSID proxying or wbadmin.msc without log-on).
- T1219detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notifications of prior activity, which can surface anomalous or unauthorized use of remote access tools that rely on authentication sessions, but this is limited to the authentication moment and does not broadly instrument the technique's post-auth C2, installation, or runtime behaviors across platforms.
- T1219prevents — A.8.5 mandates strong/MFA authentication, log-on hardening (brute-force protection, no cleartext, session termination, alerts on failures) and strength proportionate to data sensitivity; this directly stops an adversary from successfully authenticating and using/abusing a remote access tool (including post-compromise or built-in features) on most platforms and usage scenarios, with the bounded remainder being already-authenticated sessions, legitimate admin use, or MFA-exempt service accounts.
- T1219.001detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or thresholds like repeated failures, and monitoring for anomalous access patterns (unusual location/device/time) that can surface IDE tunneling when it uses developer-account authentication or triggers log-on anomalies, but this is limited to the authentication surface and does not broadly detect the tunneling, persistence, or C2 behaviors themselves.
- T1219.001prevents — A.8.5 mandates strong, MFA, and hardened log-on procedures (including brute-force protection, session termination, and non-cleartext transmission) that can stop unauthorized use of IDE accounts (e.g. GitHub) or tunnels from compromised endpoints; this reaches only a slice because the technique can still be launched from an already-authenticated developer session or via auto-reconnect on a compromised host where the control's log-on rules no longer apply.
- T1219.002detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior activity; these surface anomalous or unauthorized use of remote desktop software for C2 but only for the authentication slice, not the broader technique of installing/using allowed RMM tools without new logons.
- T1219.002prevents — A.8.5 requires MFA, strong auth, session termination, brute-force protection and logon hardening that can stop unauthorized use of remote desktop tools when they require interactive authentication, but leaves the bulk of the technique (legitimate RMM tools already authorized inside the environment, or auth already bypassed) untouched.
- T1219.003detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events on potential breaches, and monitoring for anomalous access patterns (e.g. unusual location/device/time), which can surface hardware-based remote access sessions when they trigger authentication flows or anomalies, but the technique is primarily physical/post-compromise hardware that often bypasses software auth entirely and is outside the clause's authentication-focused scope.
- T1221prevents — A.8.5 mandates strong/MFA authentication, log-on hardening (no cleartext, brute-force protection, session termination, separate-channel last-logon info) and credential-prompting safeguards that stop many injected credential-harvesting URLs from succeeding, but leaves the initial template-reference injection, payload fetch, and non-authentication abuse paths (e.g. remote code execution) untouched.
- T1484detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches of log-on controls, and displaying prior logon details, which can surface anomalous policy modifications that affect authentication (e.g. rogue federation or trust changes), but this is limited to authentication events rather than the full range of domain/tenant policy abuse vectors like GPO changes or rogue DCs.
- T1484prevents — A.8.5's MFA, strong auth, log-on hardening, brute-force protection, and session termination raise the bar for initial access and credential abuse needed to obtain the permissions that enable T1484, but do not stop an already-privileged adversary (or one who bypasses auth) from modifying domain/tenant policy settings.
- T1484.002detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior logon details, which can surface anomalous trust modifications that affect authentication (e.g. new federated IdP or altered claims), but only for a minority slice of observable logon events rather than the broader trust configuration changes themselves.
- T1484.002prevents — A.8.5 requires strong, MFA-based authentication techniques (with rules for unusual access patterns) and secure log-on procedures that directly stop many trust-modification attacks from successfully authenticating or escalating via forged/federated credentials; however, it does not constrain the adversary's ability to first gain the initial privileged access needed to modify the trust objects themselves.
- T1496.004detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failures, and separate-channel notifications of prior activity, which can surface anomalous SaaS usage patterns indicative of hijacking (e.g. sudden high-volume sends or unexpected enablement), but only for authentication events and not the subsequent resource-intensive abuse itself.
- T1496.004prevents — A.8.5 mandates strong, MFA-based authentication (with anti-brute-force, session termination, and anomaly alerting) proportionate to data classification; this stops adversaries from obtaining the initial credentials or session needed to compromise and then hijack SaaS resources for resource abuse, though some edge cases (e.g., already-compromised sessions, non-auth weaknesses, or exempted legacy accounts) remain.
- T1505.003detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events on potential breaches (e.g. brute-force or anomalous patterns), and separate-channel notifications of prior activity, which can surface web shell access attempts or anomalous sessions but does not broadly instrument for the web shell artifact or its command execution.
- T1505.005detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches of log-on controls, and monitoring for anomalous access patterns (unusual location/device/time) that can surface RDP/Terminal Services abuse after the fact; this is genuine detection but only a slice of the technique, which is a one-time DLL modification/patch that does not necessarily involve a new log-on event or observable anomaly at the authentication boundary.
- T1528detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior activity; this surfaces many token-theft vectors that involve authentication or OAuth grant flows, but the control is silent on token theft that bypasses log-on procedures (e.g. container compromise, IMDS requests, or refresh-token theft after initial grant), so only a slice is covered.
- T1528prevents — A.8.5 mandates strong, MFA-based authentication techniques (with anti-brute-force, session termination, no-cleartext, and context-aware rules) that directly stop many token-theft vectors (OAuth phishing, IMDS abuse, weak service-account auth, brute-forced refresh tokens); the bounded remainder is post-compromise theft from already-authenticated containers/CI pipelines where the initial authentication succeeded.
- T1529detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notifications of prior activity, which can surface anomalous shutdown/reboot attempts that require privileges or follow other impacts, but this is limited to logon-related vectors and does not broadly instrument the many non-authentication paths (API calls, CLI, hypervisor, etc.) described in the technique.
- T1530detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and notifying users/admins of anomalous logons (prior success time, failed attempts since last), which surfaces some T1530 access via leaked credentials or weak auth but does not address unauthenticated public/misconfigured bucket access that needs no credentials at all
- T1530prevents — A.8.5 mandates strong, MFA, brute-force protection, session termination, and credential safeguards that stop unauthenticated, weak-credential, or brute-forced access to cloud storage objects; the bounded remainder is misconfigured public/anonymous buckets that require no authentication at all.
- T1531detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and notifying on last-login details, which surfaces many T1531 manipulations (esp. credential changes, lockouts, or anomalous access patterns) but does not address account deletion, Group Policy disables, esxcli removal, or non-logon manipulations outside its authentication scope.
- T1534detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or repeated failures, and separate-channel notifications of prior activity, which surfaces anomalous internal credential-use or phishing-driven logons; this is a genuine but minority slice of the multi-staged T1534 campaign (device control, chat-based delivery, impersonation, and non-logon payload stages remain unseen).
- T1534prevents — A.8.5 mandates strong/MFA authentication, anti-brute-force measures, no cleartext passwords, session termination, and logon procedure hardening that directly stops credential compromise via internal phishing payloads or fake login sites, preventing the technique from succeeding; mostly because device compromise (the other initial vector) and already-compromised accounts fall outside authentication strength.
- T1537detects — A.8.5 requires logging of successful/unsuccessful logons plus raising security events on detected breaches or anomalous patterns (unusual location/device/time), which can surface adversary authentication to a cloud account used for internal transfers, but this is limited to the auth step and does not broadly detect the data transfer, sharing links, SAS URIs, or backups themselves.
- T1538detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and notifying on prior failed attempts; this surfaces use of stolen credentials on a cloud dashboard (a form of log-on) but only for the authentication slice, not the subsequent enumeration or dashboard-specific discovery that follows successful access.
- T1538prevents — A.8.5 mandates strong, MFA-based authentication (with failed-attempt limits, session termination, and other log-on hardening) proportionate to data classification; when enforced it stops stolen-credential use of the cloud dashboard, preventing the technique from succeeding, with a bounded remainder of exempted/legacy identities or MFA-bypass edge cases.
- T1539detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior log-on details; these surface anomalous session-cookie usage that deviates from expected patterns (e.g. unusual location/time/device), but do not broadly instrument cookie theft vectors such as malware scraping memory/disk, JS injection, or AiTM proxies.
- T1539prevents — A.8.5 mandates MFA, strong auth, session termination, no cleartext transmission, brute-force protection, and logon procedure hardening that directly stop many vectors for stealing/using session cookies (e.g. network sniffing, long-lived sessions, MFA bypasses, phishing proxies); residual slice remains for post-auth local theft via malware/JS injection or memory scraping where the control's auth focus does not reach.
- T1543.005prevents — A.8.5's strong/multi-factor auth, log-on hardening, brute-force protection and session controls can stop an adversary from authenticating to obtain the privileged (often root) access needed to run/modify docker/podman/kubelet commands or deploy DaemonSets, but the technique can still be executed by already-authenticated sessions, misconfigured services, or non-authentication vectors such as exploited vulnerabilities or container breakout.
- T1546detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches (e.g. repeated failures), and separate-channel notifications of prior activity, which surfaces anomalous logon-triggered execution but only for the logon subset of T1546 triggers (not app/binary/cloud events or post-gain trigger modifications).
- T1546prevents — A.8.5's strong/multi-factor auth, logon procedure hardening (no info leaks, brute-force protection, session termination, MFA on anomalies), and credential protections directly stop adversaries from gaining the authenticated access needed to create/modify event triggers for T1546 persistence/escalation on most platforms.
- T1546.002detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (including after repeated failures), and displaying prior failed attempts on next successful log-on; these surface anomalous inactivity-triggered execution when it touches authentication surfaces, but the technique's core (registry manipulation of SCRNSAVE.exe/ScreenSaveTimeout with ScreenSaverIsSecure=0) has no authentication involvement and is unseen by this control.
- T1546.002prevents — A.8.5 explicitly requires terminating inactive sessions after a defined period (k) and restricting connection duration for high-risk apps (l), which directly constrains the inactivity window and screensaver trigger used by T1546.002; this is only a slice because the control is scoped to authentication strength and log-on procedures rather than comprehensively blocking all registry-based screensaver abuse or non-auth-related persistence.
- T1546.003detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches (including brute-force or anomalous patterns), and monitoring for suspicious log-on behavior, which can surface some WMI event subscriptions tied to user login events but does not broadly instrument or detect arbitrary WMI subscriptions (e.g. those based on wall-clock time or uptime).
- T1546.003prevents — A.8.5's MFA, strong auth, log-on hardening, brute-force protection, session termination and separate-channel notifications constrain credential-based or interactive-login triggers (including user-login WMI events) and raise alerts on anomalies, but do not block non-interactive WMI subscription creation/registration or execution via mofcomp.exe or WmiPrvSe.exe.
- T1546.007detects — A.8.5 requires logging of successful/unsuccessful logons plus raising security events/alerts on detected breaches of log-on controls; this surfaces anomalous netsh.exe execution or registry changes tied to helper DLL registration when they intersect with authentication flows, but the control's scope is narrowly log-on oriented and does not broadly instrument arbitrary persistence or netsh helper loading outside that boundary.
- T1546.008detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches of log-on controls, and separate-channel notification of prior failed attempts, which surfaces anomalous pre-login or unauthorized use of accessibility features at the logon screen; this is a genuine but minority slice of the full technique (binary/registry replacement itself is not instrumented).
- T1546.008prevents — A.8.5 requires strong/MFA authentication, log-on procedure hardening (no info/help before success, brute-force protection, session termination, no cleartext passwords), and alerts on failed logons; these stop many unauthenticated or brute-forced uses of accessibility backdoors at the login screen or RDP but do not stop binary/registry replacement of the features themselves or their use after an initial legitimate login.
- T1546.012detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches of log-on controls, and monitoring for anomalous access patterns (e.g. unusual location/device/time), which can surface some IFEO-based persistence or privilege-escalation artifacts at login or process-launch time but does not broadly instrument Registry changes, silent-exit monitors, or non-logon IFEO abuse.
- T1546.014detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (including on authentication-related events that emond can trigger), which surfaces the technique when it uses user-authentication events; this is only a slice of the full technique surface (other events, rule installation, privilege-escalation path).
- T1546.014prevents — A.8.5 mandates strong/MFA authentication, log-on hardening (no brute-force, no cleartext, session termination, alerts on failures) and rules-based factors that can block unauthorized authentication events; this directly stops the 'user authentication' trigger for emond rules on macOS, but leaves system-startup and other non-auth events (plus privilege-escalation path) untouched.
- T1546.015detects — A.8.5 requires logging of successful/unsuccessful logon attempts, raising security events/alerts on potential breaches of log-on controls, and anomalous logon patterns (unusual location/device/time) that can surface COM hijacking when it triggers authentication or execution flows; this is a genuine but minority slice of the technique's stealthy Registry-based persistence that does not require or trigger logon.
- T1546.016detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior logons — these surface anomalous installer-driven privilege events when they intersect with authentication flows, but the technique's core (tampered postinst/maintainer/.msi scripts executing outside any log-on) sits outside that scope.
- T1547detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior log-on details; this surfaces anomalous autostart behavior tied to logon but only for the logon slice of T1547, not boot/kernel/registry mechanisms on other platforms or non-logon vectors.
- T1547prevents — A.8.5's MFA, strong auth, log-on hardening (brute-force protection, no cleartext, session termination, alerts) and credential safeguards raise the bar for adversaries abusing autostart mechanisms that rely on stolen credentials or weak logon, but do nothing against kernel modifications, registry/boot changes, or already-elevated persistence that bypasses authentication entirely.
- T1547.001detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and informing the user of prior unsuccessful attempts; this surfaces anomalous or suspicious startup activity tied to logon but only for the logon event itself, not for the prior registry/startup-folder modification that enables T1547.001.
- T1547.001prevents — A.8.5's log-on procedure rules (brute-force protection, MFA for critical systems, session termination, no clear-text creds) raise the bar for an adversary to obtain the credentials needed to log in and thereby trigger the run-key/startup-folder payload, but do nothing to stop the adversary from writing the persistence entry itself while already authenticated or from using non-interactive boot-time mechanisms.
- T1547.002detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous patterns such as unusual locations/devices/times, which can surface suspicious authentication package activity at LSA load time; however the clause's scope is user/entity logon procedures rather than low-level LSA boot-time autostart abuse, leaving most of the technique outside its direct view.
- T1547.004detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior logons and failed attempts; these surface anomalous Winlogon activity at login time but do not broadly instrument the registry modifications or helper-DLL loading itself.
- T1547.004prevents — A.8.5's log-on procedure rules (esp. brute-force protection, MFA for critical systems, no cleartext creds, session termination, and alerts on failed logons) raise the bar for an adversary to authenticate and reach the Winlogon helper-DLL abuse point, but do not stop a privileged user or prior foothold from modifying the registry keys themselves.
- T1547.005detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, and monitoring for anomalous access patterns (unusual location/device/time), which can surface SSP abuse that yields credentials or runs at boot; this is a genuine but minority slice of the technique's full surface (registry modification and LSA DLL load).
- T1547.012detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, and monitoring for anomalous access patterns (e.g. unusual location/device/time), which can surface some abuse of the print spooler during boot or anomalous SYSTEM-level DLL loading but does not broadly instrument or detect the specific registry/API/installation steps of this technique.
- T1547.014detects — A.8.5 requires logging of successful/unsuccessful logons plus raising a security event on detected breaches of log-on controls, which surfaces anomalous logon-triggered execution such as Active Setup malware; this is a genuine but minority slice of the technique (most execution artifacts live outside the logon surface and are unseen by authentication-focused logging).
- T1547.015detects — A.8.5 explicitly requires logging successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior log-on details, which surfaces anomalous login-item-driven execution at login time on macOS; this is genuine detection of the technique in flight but only a slice (logon events), not the addition step itself or non-logon artifacts.
- T1548detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and displaying prior log-on details, which surfaces many (but not all) abuse-elevation events that involve authentication or log-on steps.
- T1548prevents — A.8.5 mandates strong, MFA, and hardened logon procedures (brute-force protection, no cleartext, session termination) that stop most native elevation-control bypasses (UAC prompts, sudo abuse, credential theft) by requiring proper authenticated authorization before higher privileges are granted; the bounded remainder is platform-specific or non-interactive bypasses outside interactive logon.
- T1548.002detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior logons/failures; these surface some UAC bypasses that involve anomalous authentication or elevation but miss the bulk of technique variants that abuse auto-elevation, COM objects, process injection, or lateral movement without triggering logon events.
- T1548.002prevents — A.8.5 mandates strong/MFA authentication, log-on hardening (no cleartext, brute-force protection, session termination, alerts on failures) and appropriate strength for classified information; these stop many UAC-bypass vectors that rely on weak credential use, stolen passwords, or unauthenticated elevation, but leave intact the large remainder of bypasses that abuse auto-elevation, COM hijacks, process injection, or lateral movement with already-known admin credentials.
- T1548.003detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior unsuccessful attempts; these surface sudo caching or NOPASSWD abuse when it triggers an authentication flow, but the technique can succeed without any authentication event at all (e.g. timestamp still fresh or sudoers misconfiguration granting passwordless elevation), so only a minority slice is detected.
- T1548.003prevents — A.8.5 mandates strong, multi-factor, and properly configured authentication (including re-prompting, session termination, and brute-force protection) that directly stops sudo caching abuse and weak sudoers NOPASSWD configurations from allowing unauthenticated elevation; the bounded remainder is non-interactive or already-compromised sessions where the control's log-on focus does not reach.
- T1548.004detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and separate-channel notification of prior activity, which surfaces anomalous privilege-prompt behavior when it occurs; this is limited to a slice because the control is scoped to authentication flows rather than all elevated-execution calls or the macOS-specific API abuse.
- T1548.004prevents — A.8.5 mandates strong/MFA authentication, log-on hardening (no cleartext, brute-force protection, session termination, separate-channel last-logon info) and appropriate strength for the classification of information accessed; this directly constrains the user-credential prompt surface of T1548.004 on macOS (including MFA where required and blocking brute-force or sniffing), but leaves the deprecated API's lack of origin/integrity checks, world-writable file loading, and masquerading of the calling program as residual attack surface.
- T1548.005detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and notifying on prior unsuccessful attempts, which surfaces abuse of just-in-time, impersonation or PassRole mechanisms when they involve authentication or log-on events; this is only a slice of the technique (many escalation paths are permission-configuration or post-auth, not observable at log-on).
- T1548.005prevents — A.8.5 mandates strong, MFA-based authentication (with anti-brute-force, session termination, and log-on hardening) that stops many misconfigurations from being directly abused for temporary elevation or impersonation; it does not reach the distinct permission-assignment and role-passing mechanisms that enable the technique when admins misconfigure them.
- T1548.006detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches of log-on controls, and monitoring for anomalous access patterns (e.g. unusual location/device/time), which can surface TCC manipulation when it involves anomalous authentication, permission grants, or injected processes tied to log-on, but this is limited to the authentication slice and does not broadly detect database manipulation, SIP bypass, or non-auth TCC abuse vectors.
- T1548.006prevents — A.8.5 requires strong/multi-factor authentication and hardened log-on procedures (including brute-force protection, session termination, and no cleartext credentials) that can stop an adversary from obtaining the initial credentials or session needed to reach a TCC-protected resource or to run the abusing process, but the control does not address TCC database manipulation, SIP bypass, process injection, or inherited permissions once access is obtained.
- T1550detects — A.8.5 explicitly requires logging unsuccessful/successful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and using MFA/strong auth that can surface anomalies, which surfaces use of stolen alternate auth material in many but not all cases (e.g. pass-the-hash or ticket use often evades logon-focused detection).
- T1550prevents — A.8.5 mandates strong, multi-factor, and hardened log-on procedures (MFA, brute-force protection, no cleartext transmission, session termination) that stop most alternate material from being issued or usable for lateral movement; the bounded remainder is already-issued material (e.g., stolen Kerberos tickets or cached tokens) that survives until expiry.
- T1550.001detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on detected breaches or thresholds like repeated failures, and separate-channel notifications of prior activity; this surfaces anomalous token-based access that aligns with or follows authentication events, but the technique's post-auth API use (often without new logons, hard to distinguish from legitimate workflows, and bypassing MFA/password changes) leaves most realizations outside the control's authentication-focused scope.
- T1550.001prevents — A.8.5 mandates strong, MFA-based authentication techniques (with factors, rules/patterns, session termination, brute-force protection, and no clear-text transmission) that directly stop stolen tokens from being usable in lieu of credentials for most OAuth/API flows; the bounded remainder is token theft after successful initial auth plus the explicit note that token use negates a second factor.
- T1550.002detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous patterns such as unusual location/device/time; these surface PtH attempts in flight or post-authentication but only where they intersect the log-on procedure or anomaly rules, leaving the bulk of hash capture, ticket manipulation, and non-logon lateral movement outside the clause's defined scope.
- T1550.002prevents — A.8.5 mandates strong/multi-factor authentication techniques, MFA under risk conditions, no cleartext passwords over networks, brute-force protections, and session termination, which prevent PtH by blocking hash-only authentication paths in most modern configurations (though legacy NTLM/Kerberos hash reuse remains a bounded remainder).
- T1550.003detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and displaying prior log-on details, which surfaces anomalous PtT use of stolen or forged Kerberos tickets during authentication.
- T1550.003prevents — A.8.5 mandates strong, MFA, non-password, and anti-brute-force authentication methods plus session controls that stop stolen-ticket reuse in most realistic PtT scenarios (especially where MFA or alternative factors are enforced or tickets are short-lived/renewal-protected); the bounded remainder is pure Kerberos environments where a captured valid TGT/service ticket is accepted without re-authentication.
- T1550.004detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior log-on details, which surfaces anomalous use of a stolen session cookie as a detectable log-on anomaly; this is only a slice because the control is scoped to log-on procedures rather than ongoing session-cookie replay or post-authentication activity across all platforms.
- T1550.004prevents — A.8.5 mandates MFA (and other strong auth techniques) proportionate to data classification plus session protections (inactivity timeout, connection duration limits, no cleartext transmission) that directly stop many session-cookie replay attacks; the bounded remainder is long-lived cookies obtained post-auth from already-compromised sessions or MFA-bypassing malware that the clause does not universally eliminate.
- T1552prevents — A.8.5 requires strong/MFA authentication, protected log-on procedures, no cleartext transmission/storage of passwords, session termination, and brute-force protections, which stop many unsecured-credential techniques (e.g. plaintext sniffing, weak password reuse, exposed keys) from yielding access; it leaves the core search-and-obtain action on already-misplaced credentials (registry, shell history, private keys) untouched.
- T1552.001prevents — A.8.5 mandates MFA, strong auth methods, no cleartext passwords/transmission, session termination, and brute-force protections that stop many (but not all) uses of credentials found in files, especially for interactive logons; it does not stop non-interactive credential reuse, embedded secrets in configs, or extraction from backups/VMs.
- T1552.004detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (including brute-force on passphrases), and separate-channel notifications of prior activity; this surfaces some T1552.004 activity (e.g. passphrase brute-force or anomalous key use for auth) but does not address file searches, exports, or key discovery itself.
- T1552.004prevents — A.8.5 mandates strong/multi-factor authentication techniques, protects credential entry/transmission, and limits brute-force guessing of passphrases on discovered keys, which stops many (but not all) uses of found private keys for authentication or impersonation.
- T1552.005detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous access patterns (unusual location/device/time) that can surface credential access via the Instance Metadata API, but this is limited to authentication events rather than the broader technique of querying the metadata endpoint itself.
- T1552.005prevents — A.8.5 mandates strong/MFA authentication, hardened log-on procedures, and session controls that stop many credential-theft paths (including those that later query metadata APIs), but the technique can still succeed via SSRF against a public proxy or from an already-authenticated foothold on the instance itself.
- T1552.006detects — A.8.5 requires logging of successful/unsuccessful log-on attempts plus raising security events on detected breaches of log-on controls, which surfaces the enumeration and decryption activity when it triggers authentication flows or anomalous access patterns, but the core technique of reading/decrypting static GPP XML files from SYSVOL does not inherently involve log-on and can occur without triggering these controls.
- T1552.006prevents — A.8.5 mandates strong/multi-factor authentication, protected log-on procedures, brute-force defenses, session termination, and no clear-text credential transmission; these stop domain users from authenticating to read/decrypt GPP XMLs in SYSVOL (the core access vector), with only a bounded remainder for legacy/service accounts exempted from MFA.
- T1552.007detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous access patterns (unusual location/device/time) that can surface credential-gathering via container APIs when it triggers auth flows; this is a genuine but minority slice of the technique (only the auth step, not direct API credential retrieval or non-auth API abuse).
- T1552.007prevents — A.8.5 mandates strong, MFA, and hardened log-on procedures (including brute-force protection, no cleartext transmission, session termination) that stop credential-gathering via unauthenticated or weakly-authenticated container APIs; the bounded remainder is already-authenticated sessions or service-account tokens inside the container that the control does not reach.
- T1552.008detects — A.8.5 explicitly requires logging unsuccessful/successful log-on attempts, raising security events/alerts on detected breaches or excessive failures, and monitoring for anomalous patterns (unusual location/device/time) that can surface credential exposure in chat/services, but this is scoped only to authentication events rather than general chat-message content or credential-passing artifacts.
- T1552.008prevents — A.8.5 mandates MFA, strong auth, no cleartext passwords, brute-force protection, session termination, and logon design that together stop many (but not all) ways credentials can be sent or stored unsecured in chat, especially on SaaS/Office platforms where the control's auth requirements apply at access time.
- T1553prevents — A.8.5 mandates strong/multi-factor authentication techniques, log-on protections against brute-force, MFA for critical systems, and rules-based additional factors (e.g. unusual location/device/time), which directly prevents the successful execution of T1553 sub-techniques that rely on stolen/created certificates or modified trust attributes to bypass warnings or execution blocks on untrusted code.
- T1553.004detects — A.8.5 explicitly requires logging successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and monitoring for anomalous access patterns (unusual location/device/time) that would surface many real-world root-certificate installs performed post-compromise to enable MitM or spoofed TLS.
- T1553.006detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior log-on details, which surfaces anomalous authentication-related activity that can include policy-modification attempts when they involve elevated logons or kernel/debug-mode access.
- T1555detects — A.8.5 requires logging of successful/unsuccessful log-on attempts plus raising security events/alerts on detected breaches or brute-force patterns, which surfaces some T1555 realizations (e.g. mass extraction from stores triggering anomalous logons) but does not instrument or surface the core technique of searching common storage locations itself.
- T1555prevents — A.8.5 mandates strong, MFA, brute-force protection, session termination, and non-cleartext handling that stop many common password-store theft vectors (e.g. sniffing, guessing, reuse after compromise); the bounded remainder is direct filesystem/memory scraping of already-stored plaintext or weakly-protected manager vaults on a compromised host.
- T1555.001detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and separate-channel notifications of prior activity, which can surface anomalous credential access from Keychain on macOS; this is only a slice of the technique (focused on logon events rather than direct file/memory reads or security command use).
- T1555.001prevents — A.8.5 mandates strong/multi-factor authentication, secure log-on procedures (no cleartext passwords, brute-force protection, session termination, MFA on critical systems), and appropriate strength keyed to data classification; this directly stops the adversary from reaching the point where they can run `security dump-keychain` or read the keychain file under an authenticated session on macOS.
- T1555.002prevents — A.8.5 mandates strong/multi-factor authentication techniques, protection of authentication information in transit and at rest, and log-on procedures that explicitly reduce unauthorized-access risk (including brute-force resistance and session termination); these directly stop the root-level memory read from yielding usable plaintext credentials in the dominant modern case (post-El Capitan, where the master key is no longer cached in plaintext), leaving only a bounded legacy remainder.
- T1555.003detects — A.8.5 explicitly requires logging successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and related monitoring of authentication activity, which can surface browser credential theft when it triggers anomalous logons or patterns; this is only a slice because the technique can succeed via file/memory reads without any logon event or detectable anomaly.
- T1555.003prevents — A.8.5 mandates MFA, strong auth, brute-force protections, session termination, no cleartext passwords/transmission, and logon design that collectively stop most browser credential theft techniques (especially reuse, memory scraping, and weak storage) from succeeding; the bounded remainder is post-compromise file reads on already-authenticated sessions where the control's scope ends at authentication strength rather than credential isolation.
- T1555.004detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior logons/failures; these surface Credential Manager access/abuse when it triggers a log-on or authentication flow, but the technique can also occur via direct file reads, vaultcmd.exe, APIs, or backups outside any log-on procedure.
- T1555.004prevents — A.8.5 mandates strong/multi-factor authentication techniques, protected log-on procedures, brute-force defenses, MFA for critical systems, and no clear-text transmission of credentials, which directly stops most Windows Credential Manager abuse paths that rely on weak or captured authentication material (including NTLM/Kerberos sign-ins and password recovery).
- T1555.005detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and separate-channel notification of prior failed attempts, which surfaces brute-force guessing of a master password; it does not address memory extraction or exploitation of an already-unlocked manager.
- T1555.005prevents — A.8.5 mandates strong/multi-factor authentication, master-password brute-force protections, session termination, and log-on hardening that stop the technique from succeeding in the great majority of cases; the bounded remainder is in-memory extraction of already-unlocked plaintext after legitimate unlock.
- T1555.006detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior activity; these surface anomalous access to secrets managers when it uses an authentication flow, but the clause is silent on API-level secret retrieval, privilege-abuse patterns, or non-logon credential exfiltration, leaving most of the technique outside its view.
- T1555.006prevents — A.8.5 mandates MFA, strong auth proportionate to data classification, brute-force protections, session termination, and no cleartext transmission; these block the initial privilege acquisition (e.g. compromised accounts) that the technique requires before any secret retrieval API call can succeed, though once sufficient privileges exist the technique itself is not blocked.
- T1556detects — A.8.5 explicitly requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or repeated failures, and separate-channel notifications of prior activity, which surfaces anomalous authentication-process modifications in flight or after the fact; this is only a slice because the control is scoped to log-on procedures rather than directly instrumenting or broadly monitoring the underlying mechanisms (LSASS, PAM, plugins) named in T1556.
- T1556prevents — A.8.5 mandates strong, multi-factor, protected, and hardened authentication techniques (including MFA, brute-force protection, no cleartext, session termination, and alternative factors) that directly stop most forms of authentication-process modification from succeeding in bypassing or revealing credentials, with a bounded remainder for implementation-specific or exempted components.
- T1556.001detects — A.8.5 explicitly requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous patterns such as unusual location/device/time; these surface the anomalous authentications enabled by a domain controller patch, but only after the fact and without guaranteed coverage of in-memory LSASS patching itself.
- T1556.001prevents — A.8.5 mandates strong/multi-factor authentication techniques, log-on hardening (brute-force protection, no cleartext, session termination, alerts on failures) and appropriate strength for classified information, which stops many bypass vectors and forces the adversary to also compromise the added factors or mechanisms; however, it does not address in-memory patching of the domain controller's own authentication process (LSASS) itself, leaving a genuine residual slice of the technique reachable.
- T1556.002detects — A.8.5 explicitly requires logging unsuccessful/successful log-on attempts, raising security events/alerts on potential breaches or repeated failures, which surfaces anomalous password-filter activity during authentication but does not broadly instrument or guarantee discovery of the malicious DLL registration itself.
- T1556.002prevents — A.8.5 mandates strong/multi-factor authentication techniques, log-on protections against brute-force and credential exposure, and rules that reduce unauthorized access success; these stop most (but not all) malicious password-filter DLLs from successfully harvesting usable credentials during validation.
- T1556.003detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and other observable indicators that surface anomalous PAM-mediated authentication activity, but this is scoped only to log-on procedures rather than the underlying PAM component modification or credential-harvesting code injection itself.
- T1556.003prevents — A.8.5 mandates appropriate-strength authentication (MFA, alternative factors, brute-force protection, no cleartext transmission, session termination) that directly stops the backdoor or credential-harvesting PAM module from successfully granting or stealing access, with the bounded remainder being pre-boot or out-of-PAM mechanisms that the control does not reach.
- T1556.005detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior failed attempts, which surfaces the anomalous enabling of reversible encryption or related credential-access activity when it triggers log-on or policy events; this is only a slice because the control is scoped to authentication events rather than AD property changes or FGPP modifications themselves.
- T1556.005prevents — A.8.5 requires strong/multi-factor authentication techniques, log-on protections against brute-force, no cleartext passwords/transmission, and session termination, which prevent many paths to credential abuse but do not stop an adversary from enabling reversible encryption via policy/PowerShell or extracting the specific decryption components post-enablement.
- T1556.006detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on detected breaches or excessive failures, and notifying users/admins of anomalous log-on details, which surfaces adversary MFA modification or bypass in flight or after the fact on covered authentication paths.
- T1556.006prevents — A.8.5 mandates MFA (plus adaptive rules, brute-force protection, and log-on hardening) whose presence and strength stop the adversary from disabling or bypassing MFA to achieve persistent access; the named remainder is post-compromise privileged abuse of legitimate features (e.g. Azure Conditional Access exclusions) that the control's requirements do not reach.
- T1556.007detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and displaying prior log-on details, which surfaces anomalous hybrid-authentication behavior (e.g. unexpected tokens, new PTA agents, or mass successful logons) once it occurs; this is genuine detection but only a minority slice of the technique, which primarily lives in on-premises process injection, config tampering, and cloud admin actions outside normal log-on procedures.
- T1556.007prevents — A.8.5 mandates strong/multi-factor authentication techniques, log-on hardening (brute-force protection, no cleartext, session termination, MFA under anomalous conditions) and appropriate strength for classified information, which directly constrains or blocks many hybrid backdoor vectors (e.g. credential harvesting, weak MFA bypass, unauthorized logons); however, it does not address on-premises process patching, DLL injection into PTA/AD FS agents, or cloud-side PTA agent registration that subverts the authentication pipeline itself.
- T1556.008detects — A.8.5 explicitly requires logging unsuccessful/successful log-on attempts, raising a security event/alert on potential breaches or excessive failures, and monitoring for anomalous patterns (unusual location/device/time) that can surface the anomalous credential-manager registration or logon activity, but does not mandate detection of the specific Registry-based DLL installation or NPLogonNotify hook itself.
- T1556.008prevents — A.8.5 mandates strong/multi-factor authentication, no cleartext transmission of passwords, protected log-on procedures, and brute-force protections that stop the captured credentials from being usable for unauthorized access; the technique still runs on Windows but is prevented from achieving its goal in the bulk of covered scenarios, with a nameable remainder (e.g. exempted legacy paths or non-MFA identities).
- T1556.009detects — A.8.5 explicitly requires logging unsuccessful/successful log-on attempts, raising a security event/alert on potential breaches or excessive failures, and using contextual rules (unusual location/device/time) that surface anomalous access patterns, which would detect modifications to or bypasses of conditional access policies; partial because the clause sets requirements rather than mandating universal instrumentation depth or coverage of all policy-modification vectors (e.g., direct IAM condition edits outside monitored log-on flows).
- T1556.009prevents — A.8.5 explicitly requires MFA, risk-based rules (unusual location/device/time), and log-on protections that directly implement or mandate the conditional verifications adversaries target in T1556.009; the named remainder is that the control sets requirements rather than universally enforcing the underlying policy objects themselves.
- T1557detects — A.8.5 explicitly requires logging unsuccessful/successful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and using MFA/strong auth that can surface anomalies, which surfaces some AiTM attempts (especially those targeting credentials or sessions); this is only a slice because the control is scoped to authentication flows and does not broadly instrument network positioning, ARP/DNS abuse, or non-logon traffic manipulation.
- T1557prevents — A.8.5 mandates strong/MFA authentication, no cleartext passwords or transmission, session termination, brute-force protection, and downgrade-resistant logon procedures that directly stop credential theft, sniffing, and replay that AiTM is used to enable.
- T1557.001detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and separate-channel notifications of prior activity, which can surface anomalous authentication material collection or relay attempts in some scenarios but does not broadly instrument or detect the preceding name-resolution poisoning itself.
- T1557.001prevents — A.8.5 mandates strong/MFA authentication, protected log-on procedures, no cleartext passwords or transmission, session termination, and brute-force protections; these stop most LLMNR/NBT-NS/mDNS poisoning + relay from succeeding in granting unauthorized access (the technique's goal), with the bounded remainder being legacy/NTLMv1 paths or exempted identities that the control itself names as allowable.
- T1557.004detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on detected breaches or excessive failures, and separate-channel notification of prior failed attempts; these surface the fake captive-portal credential harvest that realises T1557.004, but the control is silent on Wi-Fi association/probe detection itself and the remainder (pre-logon evil-twin signalling, stronger-signal coercion, certificate forgery) is outside its authentication-logic scope.
- T1557.004prevents — A.8.5 mandates MFA, strong auth, no cleartext passwords over networks, session termination, and logon protections that stop credential capture or unauthorized access on the evil twin network for many (but not all) scenarios, especially when devices enforce cert pinning or users heed warnings; it does not stop the initial deceptive connection, probe-response impersonation, or all captive-portal phishing vectors.
- T1558detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and informing users of prior unsuccessful attempts, which surfaces anomalous Kerberos ticket activity when it triggers log-on events; this is only a slice because the control is scoped to log-on procedures rather than comprehensively monitoring ticket theft/forgery artifacts like LSASS memory, klist usage, or Golden/Silver ticket patterns across the full technique.
- T1558prevents — A.8.5 mandates strong/multi-factor authentication techniques, MFA under anomalous conditions, protected log-on procedures, brute-force protections, no cleartext passwords/tickets in transit or on entry, and session termination — all of which stop most Kerberos ticket theft or forgery paths from succeeding in gaining access.
- T1558.001detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and notifying on prior failed attempts, which surfaces anomalous Kerberos TGT usage or KDC interactions after the fact; partial because it is scoped to log-on procedures rather than the full golden-ticket forgery or KRBTGT-hash extraction chain.
- T1558.001prevents — A.8.5 mandates strong/multi-factor authentication techniques, log-on protections against brute-force and credential exposure, and session controls that stop forged Kerberos material from being used to gain unauthorized access; the KRBTGT compromise vector itself is outside its scope, leaving a bounded remainder.
- T1558.002detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior log-on details, which surfaces silver ticket usage when it triggers an authentication event on the target resource.
- T1558.002prevents — A.8.5 mandates strong, multi-factor authentication techniques proportionate to data classification, protects credential transmission, blocks brute-force attempts, logs/raises events on suspicious logons, and terminates sessions — all of which stop an adversary from successfully using a forged silver ticket to gain access, though the initial hash theft (via Kerberoasting or dumping) and offline forgery itself sit outside the clause's authentication focus.
- T1558.003detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or brute-force patterns, and monitoring for anomalous access (unusual location/device/time) that would surface Kerberoasting's TGS requests and offline cracking attempts; this is genuine detection but only a slice, as the core technique (TGT abuse, SPN enumeration, RC4 hash extraction from network or DC) occurs outside log-on procedures and is not instrumented by the clause.
- T1558.003prevents — A.8.5 mandates strong/multi-factor authentication, protects log-on procedures against brute-force (including rate limiting, account lockout, CAPTCHA), avoids cleartext password transmission, and terminates sessions, all of which directly stop the offline brute-force cracking step that defines successful Kerberoasting; the bounded remainder is service accounts that cannot use MFA and still rely on crackable RC4 tickets.
- T1558.004detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous patterns such as unusual locations/devices/times; these surface AS-REP roasting attempts (which rely on unauthenticated AS-REQ messages and brute-force cracking) when they trigger observable log anomalies, but only for a slice of implementations where such events are instrumented and reviewed rather than the bulk of the technique.
- T1558.004prevents — A.8.5 mandates strong authentication (MFA, alternatives to passwords, brute-force protections, no cleartext transmission) proportionate to information classification; enabling Kerberos pre-authentication (or stronger equivalents) directly stops AS-REP messages from being crackable offline, covering the dominant attack vector with only a bounded remainder of legacy or exempted accounts.
- T1558.005detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior log-on details, which surfaces anomalous Kerberos ticket activity on Linux/macOS where it intersects with authentication events; this is only a slice because the control is scoped to log-on procedures rather than ongoing credential-cache monitoring or file-access anomalies for ccache theft.
- T1558.005prevents — A.8.5 mandates strong/multi-factor authentication techniques, log-on protections against brute-force, session termination, and non-cleartext credential handling, which directly stop adversaries from obtaining usable ccache Kerberos tickets in the first place on Linux/macOS (the dominant acquisition vector for this technique); the bounded remainder is post-authentication in-memory theft or misconfigured krb5.conf locations that still allow collection.
- T1559.001detects — A.8.5 requires logging of successful/unsuccessful logon attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notifications of prior activity; these surface anomalous COM-based local execution when it triggers an authentication boundary or unusual access pattern, but the bulk of COM abuse (in-process object invocation without crossing a logon) sits outside this control's scope.
- T1559.001prevents — A.8.5 mandates strong/MFA authentication, log-on hardening (brute-force protection, no cleartext, session termination, alerts), and appropriate strength for classified information; this stops many COM-abusing client processes from successfully authenticating to invoke privileged COM objects or escalate, but leaves a large remainder (COM abuse by already-authenticated code, in-process calls, or non-authentication vectors) untouched.
- T1563detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and notifying users/admins of prior activity, which surfaces anomalous hijack indicators on remote sessions (e.g. unexpected prior logons or brute-force patterns) but only for the log-on boundary and not the post-auth hijack itself or all session telemetry.
- T1563prevents — A.8.5's MFA, strong auth, session termination after inactivity, brute-force protection, and logon procedure hardening (no cleartext, separate-channel last-logon info) stop many hijacking vectors that rely on weak single-factor sessions, credential exposure, or long-lived unattended sessions, but do not block all hijacking methods such as token theft, MITM on already-authenticated channels, or hijack of a live MFA-established session.
- T1563.001detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior log-on details, which surfaces anomalous SSH session activity after the fact; this is only a slice because the clause is scoped to log-on procedures rather than in-session agent/socket hijacking or runtime session monitoring.
- T1563.001prevents — A.8.5 mandates strong/multi-factor authentication, protection of authentication material, session termination after inactivity, and log-on procedures that block brute-force and clear-text exposure; these directly stop the initial SSH session from being established or left hijackable in the ways the technique requires, with a bounded remainder for already-active agent sockets under root compromise.
- T1563.002detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and notifying users/admins of prior unsuccessful attempts, which surfaces anomalous RDP session activity after the fact; this is only a slice of the full technique (e.g., no coverage of tscon.exe execution, session token theft without log-on, or non-logon vectors).
- T1563.002prevents — A.8.5 mandates MFA, strong auth, session termination on inactivity, brute-force protection, and logon procedure hardening that directly stop credential-less session theft via tscon.exe or equivalent by requiring re-authentication or blocking unauthorized session takeover.
- T1564.002prevents — A.8.5 requires strong, MFA-capable authentication and hardened log-on procedures that reduce unauthorized access risk; this constrains the utility of hidden accounts (especially for interactive logon) on systems built under it, but the technique can still succeed via non-interactive means, registry/plist manipulation outside auth flows, or on unmodified legacy configs.
- T1566detects — A.8.5 requires logging of log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior unsuccessful attempts, which surfaces some phishing-driven credential or session abuse after the fact; it does not broadly detect the delivery, social engineering, spoofing or link/attachment vectors of T1566 itself.
- T1566prevents — A.8.5 mandates MFA, strong auth, brute-force protection, session termination, no cleartext creds and contextual rules that stop credential phishing from yielding access; the technique runs but is prevented from achieving its access goal in the bulk of cases, with a bounded remainder (e.g. MFA-exempt identities, legacy paths, or pre-compromise social engineering that bypasses the logon procedure itself).
- T1566.001detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and separate-channel notification of prior activity, which surfaces anomalous post-attachment execution but does not address the email, attachment, or pre-execution social engineering vector itself.
- T1566.001prevents — A.8.5's MFA, strong auth, brute-force protections, session termination, and logon design reduce successful credential theft or unauthorized access post-phishing, but do not stop the social engineering delivery, attachment opening, or user execution that realize T1566.001
- T1566.002detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and separate-channel notifications of prior activity, which can surface some realized spearphishing link outcomes such as anomalous OAuth consent or device-code flows that reach authentication; this is only a slice because the technique's core (email delivery, link obfuscation, user execution before any auth) lies outside log-on procedures.
- T1566.002prevents — A.8.5 mandates strong/MFA authentication (with anti-brute-force, session termination, and logon hardening) that stops most link-driven credential theft, consent phishing, device-code phishing, and post-click token abuse from succeeding; the bounded remainder is social-engineering tricks that obtain valid credentials or tokens without ever triggering an authentication challenge.
- T1566.003detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and anomalous log-on patterns (unusual location/device/time) that can surface spearphishing-driven credential abuse or anomalous access post-delivery, but does not address the social-engineering message delivery itself on third-party services.
- T1566.003prevents — A.8.5 mandates MFA, strong auth, brute-force protection, session termination, and logon safeguards that can stop credential-theft payloads delivered via spearphishing from successfully authenticating or maintaining access; however, it does not stop the social-engineering delivery, rapport-building, or user decision to open the malicious content itself.
- T1566.004detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and MFA with contextual rules (unusual location/device/time) that can surface vishing-driven MFA abuse or anomalous access, but does not broadly instrument or detect the upstream voice call, social engineering, or pre-authentication phishing delivery itself.
- T1566.004prevents — A.8.5 mandates MFA, strong auth, brute-force protections, session termination, and log-on hardening that stop many vishing-induced credential or MFA-prompt abuses from succeeding, but the social-engineering manipulation that elicits the initial call or prompt lives outside any authentication mechanism and is untouched.
- T1569prevents — A.8.5's strong/multi-factor auth, log-on hardening, brute-force protection and session termination raise the bar for remote/local service abuse that depends on authenticated access or credentialed interaction, but do not stop local service creation/execution by an already-authenticated adversary or boot-time service abuse.
- T1569.001prevents — A.8.5 requires MFA, strong auth, session termination, brute-force protection and log-on hardening that can stop an adversary from reaching the point of running launchctl as an authenticated user or service on macOS; this is a genuine but minority slice of the technique (most launchctl abuse rides on already-authenticated sessions, LaunchAgents/Daemons, or local execution contexts outside the log-on path).
- T1569.003detects — A.8.5 requires logging of successful/unsuccessful log-on attempts plus raising security events/alerts on detected breaches of log-on controls, which can surface some systemctl abuse when it is invoked from a shell or crosses an authentication boundary; this is only a minority slice of the technique's possible invocations (e.g. in scripts, as a service manager, or non-logon contexts).
- T1574detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or brute-force patterns, and monitoring for anomalous access (unusual location/device/time) that can surface some hijack-induced execution anomalies, but this is limited to authentication events and does not broadly detect execution flow hijacks like DLL search order or registry poisoning.
- T1574.001detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and anomalous log-on patterns (unusual location/device/time) that can surface some DLL hijacking side-effects when they trigger authentication flows, but most of the technique (planting, search-order abuse, sideloading, phantom substitution) occurs without touching an authentication boundary.
- T1574.013detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and anomalous log-on patterns (unusual location/device/time) that can surface process anomalies including hijacks masked under legitimate processes; this is genuine detection but only a minority slice of the technique's in-memory PEB/WriteProcessMemory behavior which lives outside authentication flows.
- T1578detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notifications of prior activity; these surface anomalous or suspicious authentication tied to infrastructure modification attempts in IaaS but only for the authentication slice, not the broader modification, evasion or evidence-removal behaviors.
- T1578prevents — A.8.5's MFA, brute-force protection, session termination, and strong auth requirements stop many unauthorized modifications of cloud compute infrastructure that rely on stolen credentials or weak access, but do not address legitimate high-privilege accounts, insider abuse, or supply-chain compromise that can still perform T1578.
- T1580prevents — A.8.5 mandates strong, MFA-backed authentication (with anti-brute-force, session termination, and log-on hardening) that stops an adversary from obtaining or using the compromised credentials or access keys required to call the discovery APIs/CLIs in the first place; the named remainder is post-authentication discovery by an already-authorized insider or via non-auth bypasses such as public buckets.
- T1584.001prevents — A.8.5 mandates strong/MFA authentication (with failed-attempt limits, alerts, and no-cleartext rules) for accounts that control domain registration; this directly stops the password-reset, help-desk, and credential-theft vectors that enable hijacking, leaving only the minority remainder of renewal-process gaps and already-compromised cloud-provider consoles.
- T1584.005prevents — A.8.5 mandates strong/MFA authentication, brute-force protection, session termination, and log-on hardening that stops adversaries from gaining the initial footholds on third-party systems needed to build or expand a botnet; the bounded remainder is already-compromised systems or non-interactive takeover vectors that do not rely on new authentication.
- T1584.006prevents — A.8.5's MFA, brute-force protection, session termination, and strong auth requirements stop many common account compromises that enable T1584.006, but do not address all vectors (e.g. phishing outside logon, supply-chain compromise of the service, or post-compromise persistence) and apply only where the control is implemented.
- T1586prevents — A.8.5 mandates strong/multi-factor authentication, brute-force protections, MFA for critical systems, session termination, and no cleartext passwords/transmission, which directly blocks the credential-compromise vectors (phishing, brute force, reuse from dumps) named in T1586; the bounded remainder is non-technical vectors such as paying insiders.
- T1586.001prevents — A.8.5 mandates MFA, brute-force protections, no cleartext passwords, session timeouts, and strong auth proportionate to data sensitivity; these directly stop the credential-theft and brute-force vectors named for compromising social-media accounts, with only the purchase-of-credentials slice left as bounded remainder.
- T1586.002prevents — A.8.5 mandates MFA, brute-force protections, no cleartext passwords, session timeouts and strong auth proportionate to data sensitivity, which directly stops the credential-theft vectors (phishing, brute force, password reuse) that enable T1586.002; the bounded remainder is non-technical vectors such as insider sales of credentials or post-compromise thread hijacking.
- T1586.003prevents — A.8.5 directly counters the dominant credential-compromise vectors named for T1586.003 (password spraying, phishing-for-credentials, brute-force, clear-text transmission, weak log-on procedures) by mandating strength-proportionate MFA, anti-brute-force measures, no clear-text passwords, secure log-on design, and alerts; the bounded remainder is purchase of already-breached credentials and theft of application access tokens that bypass authentication entirely.
- T1587.002prevents — A.8.5 mandates strong, multi-factor, and context-aware authentication techniques (plus brute-force protections and session controls) that directly stop adversaries from using a self-signed cert to authenticate or gain initial access, with the bounded remainder being non-interactive PRE techniques that never reach an auth boundary.
- T1587.003prevents — A.8.5 mandates choosing suitable/strong authentication techniques (MFA, certificates, biometrics, brute-force protections, no cleartext transmission) proportionate to information classification; this directly stops adversaries from successfully using self-signed certificates for trust, C2, or AiTM by enforcing verification that rejects untrusted self-signed material in most deployment contexts.
- T1588.003prevents — A.8.5 mandates strong, multi-factor, non-password authentication techniques (including digital certificates) with appropriate strength for the classification of information accessed, directly raising the bar for adversaries attempting to purchase or steal code signing certificates by requiring robust identity verification and reducing unauthorized access risks during certificate issuance or use.
- T1588.004prevents — A.8.5 requires strong, multi-factor, non-password authentication techniques (certificates, tokens, biometrics) with strength matched to data classification and explicit protections against brute-force, sniffing, and unauthorized log-on assistance, directly blocking adversary use of stolen/bought certificates for access or trust abuse in most credentialed scenarios.
- T1589prevents — A.8.5 mandates MFA, strong auth, brute-force protections, no cleartext passwords, session timeouts and log-on hardening that directly stop many forms of credential/MFA-configuration harvesting (phishing, username enumeration, sniffing, brute-force) from succeeding; the named remainder is passive OSINT from public leaks or social media that the control does not address.
- T1589.001detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, which surfaces credential-gathering activity (e.g. brute-force, phishing attempts, or anomalous logons) when it interacts with protected systems; this is only a slice of the broad pre-compromise gathering methods in T1589.001 such as dark-web purchases, breach dumps, or site compromises that never touch the victim's authentication surface.
- T1589.001prevents — A.8.5 mandates MFA, strong auth, brute-force protections, no cleartext passwords, session timeouts and log-on hardening that stop many credential-gathering vectors (phishing elicitation, cookie theft, brute-force, sniffing, reuse) from succeeding; the named remainder is credentials already exposed via breaches, dark-web markets or infostealer logs that the control does not block from being gathered.
- T1595.003detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and monitoring for anomalous access patterns (unusual location/device/time) that can surface wordlist-driven probing when it triggers auth flows, but this is limited to authentication events only and does not address non-auth crawling, directory enumeration, or bucket scanning on PRE platforms.
- T1598detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (e.g. repeated failures), and separate-channel notifications of prior activity, which can surface phishing-elicited credential use during authentication but does not broadly detect the pre-authentication phishing messages or social engineering itself.
- T1598prevents — A.8.5 mandates MFA, strong auth, brute-force protections, log-on warnings, no cleartext passwords, session timeouts, and alerts on suspicious logons; these directly stop most credential-harvesting successes from T1598 phishing (the technique runs but yields nothing usable), with the bounded remainder being non-credential info or MFA-bypassing social engineering vectors.
- T1598.001prevents — A.8.5 requires MFA, strong auth, anti-brute-force measures, session termination, and log-on protections that stop many credential-harvesting outcomes of spearphishing via third-party services, but the technique itself (social engineering to elicit info) runs outside enterprise controls and can succeed without ever reaching an authenticated log-on.
- T1598.003detects — A.8.5 explicitly requires logging unsuccessful/successful log-on attempts, raising security events/alerts on potential breaches or excessive failed attempts, and using MFA/strong auth that can surface anomalies, which surfaces some spearphishing attempts (esp. those triggering logon or credential-harvest patterns); this is only a slice because the technique is pre-compromise social engineering via email/QR that often evades auth-layer detection until a click or credential entry occurs.
- T1598.003prevents — A.8.5 mandates MFA, strong auth, anti-brute-force measures, session termination, no cleartext passwords, and logon procedure hardening that directly stop credential-harvesting phishing sites (including BitB, proxy kits, and quishing) from successfully eliciting usable credentials in most scenarios; the social-engineering delivery itself is outside its scope, leaving a bounded remainder.
- T1598.004prevents — A.8.5 mandates MFA, strong auth, failed-attempt limits, session timeouts, and log-on hardening that stop many vishing-elicited credentials from successfully authenticating; it does not stop the social-engineering elicitation itself or protect non-password factors the adversary can still harvest.
- T1602.001detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, which can surface anomalous SNMP queries if they trigger auth-related patterns, but this is limited to the authentication slice and does not broadly instrument or detect MIB data collection itself.
- T1602.001prevents — A.8.5 requires strong/MFA authentication and hardened log-on procedures (including brute-force protection, no cleartext transmission, session termination) that stop unauthorized SNMP access where weak or default community strings/passwords would otherwise allow MIB queries; it does not reach SNMP's unauthenticated or community-string-only configurations that remain common on network devices.
- T1602.002detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events on potential breaches (e.g. brute-force), and alerting on anomalies like unusual access patterns, which can surface some T1602.002 instances that involve credentialed access or management protocols, but most configuration-dump activity (e.g. via SNMP read or unauthenticated SMI) falls outside authentication events.
- T1602.002prevents — A.8.5's MFA, brute-force protections, session termination, and credential-strength rules stop many authentication-based paths (e.g. weak/default creds, guessing, or sniffing) that adversaries rely on to use SNMP/SMI for config dumps, but do not block non-authentication vectors such as unauthenticated SNMP community strings, misconfigured read-only access, or protocol flaws that allow direct config export.
- T1606detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or repeated failures, and separate-channel notifications of prior activity, which can surface forged credential use in some web auth flows but not the forging act itself or all bypass scenarios.
- T1606prevents — A.8.5 mandates strong, MFA-based authentication techniques (with brute-force protection, session termination, no cleartext transmission, and context-aware rules) that stop forged web credentials from successfully authenticating, even though the technique can still generate them; the named remainder is legitimate but compromised credential material (e.g. stolen private keys) that strong auth alone cannot block.
- T1606.001detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or repeated failures, and displaying prior log-on details, which surfaces anomalous cookie-based access attempts that deviate from expected patterns or originate from unusual circumstances.
- T1606.001prevents — A.8.5 mandates strong, MFA-based authentication techniques (with factors, rules/patterns for unusual access, protected log-on procedures, brute-force resistance, no cleartext transmission, session termination) that directly stop forged-cookie bypass of authentication for web apps/services; mostly because the control sets requirements rather than a universal mechanism, leaving nameable residue for exempted identities, legacy protocols, or static secrets that can still be used in forging.
- T1606.002detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on detected breaches or excessive failures, and notifying on prior failed attempts, which surfaces anomalous SAML token usage or forgery patterns when they trigger authentication flows; this is only a slice because the control is scoped to log-on procedures rather than comprehensively monitoring forged token issuance, certificate compromise, or federation trust changes at the IdP level.
- T1606.002prevents — A.8.5 mandates strong, MFA-capable authentication techniques proportionate to data classification plus explicit protections against brute-force, credential sniffing, and session hijacking; these directly stop forged SAML tokens (and the private-key compromise that enables them) from successfully authenticating when the IdP enforces the required factors and log-on hardening, leaving only the bounded remainder of legacy or exempted federation trusts that bypass the mandated strength.
- T1608.005prevents — A.8.5 mandates strong/MFA authentication, anti-brute-force measures, secure log-on procedures, and no clear-text credential transmission; these directly stop credential-harvesting link targets (phishing pages) from succeeding when the user reaches them, though they do not stop the adversary from staging the link target itself.
- T1621detects — A.8.5 explicitly requires logging unsuccessful/successful log-on attempts, raising security events/alerts on potential breaches or excessive failed attempts, and sending notifications of prior unsuccessful attempts, which surfaces the repeated login attempts that generate MFA fatigue/push-bombardment in T1621; this is only a slice because the control's detection is scoped to log-on procedure anomalies rather than the full technique (e.g. SSPR abuse or non-brute-force MFA request generation).
- T1621prevents — A.8.5 mandates MFA (with adaptive rules for unusual location/device/time), failed-attempt limits, session termination, and other log-on hardening that directly stops credential-only adversaries from triggering or succeeding at push-bombardment/MFA-fatigue login attempts; the bounded remainder is legacy protocols, exempted identities, or SSPR paths outside the clause's MFA scope.
- T1649detects — A.8.5 explicitly requires logging successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and displaying prior log-on details, which surfaces anomalous certificate-based authentication activity once it occurs, but only for password-style or MFA log-on procedures rather than the full range of certificate theft, forgery, golden-ticket issuance, or CA-key abuse across all platforms and enrollment paths.
- T1649prevents — A.8.5 mandates suitable/strong authentication techniques (explicitly naming certificates, MFA, alternative factors, and rules-based additional factors) whose strength matches information classification, directly closing the primary authentication-abuse vector in T1649; the bounded remainder is theft of already-issued valid certificates or compromise of root CA keys, which the clause does not reach.
- T1651detects — A.8.5 requires logging of successful/unsuccessful logons, raising security events/alerts on potential breaches or excessive failed attempts, and separate-channel notifications of prior activity; these surface anomalous administrative use of cloud management services (e.g. unusual RunCommand issuance) but only for the authentication slice, not command execution itself or non-auth indicators, leaving most of the technique undetected.
- T1651prevents — A.8.5 mandates strong, MFA-based authentication (with factors, brute-force protection, session termination, and alerts) proportionate to data classification, which stops most unauthorized admin accounts from being obtained and therefore stops most abuse of cloud management services to run VM commands.
- T1657prevents — A.8.5's strong/multi-factor authentication, log-on hardening, brute-force protection and session controls directly stop many account compromises and unauthorized transfers that enable financial theft, but the technique also succeeds via social engineering, BEC impersonation, ransomware extortion and non-authentication paths that the control does not address.
- T1669detects — A.8.5 requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches (including brute-force or anomalous patterns like unusual location/time/device), which surfaces some Wi-Fi connection attempts that abuse valid accounts but does not broadly instrument wireless association, proximity-based access, or dual-homed bridging.
- T1669prevents — A.8.5 mandates strong/multi-factor authentication (plus log-on protections against brute-force, sniffing, and cleartext) that directly stops the Valid Accounts sub-technique required to join secured Wi-Fi networks, but leaves open Wi-Fi, physical proximity, and dual-homed bridge vectors untouched.
- T1671detects — A.8.5 explicitly requires logging successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and displaying prior log-on details, which surfaces anomalous OAuth consent or token-based access patterns after the fact; this is a genuine but minority slice of the technique (most of which lives in app registration, consent grants, and service-principal lifecycle outside log-on procedures).
- T1671prevents — A.8.5 mandates MFA and strong authentication (including for OAuth consent flows and service principals) plus log-on hardening that can block unauthorized creation or abuse of integrations, but the technique can still succeed via legitimate high-priv consent, legacy tokens, or post-consent persistence that survives account disablement.
- T1674detects — A.8.5 explicitly requires logging unsuccessful/successful log-on attempts, raising security events/alerts on potential breaches or excessive failed attempts, and monitoring for anomalous patterns such as unusual location/device/time, which surfaces many input-injection attempts that abuse or mimic authentication flows; this is only a slice of the broad technique (e.g. non-auth HID USB or arbitrary GUI keystroke injection is outside its scope).
- T1684prevents — A.8.5 mandates MFA, strong auth, brute-force protections, session termination, and log-on hardening that stop many social-engineering outcomes (e.g. credential theft, unauthorized password/MFA changes, session hijack) even after the user is influenced; the named remainder is direct human-authorized actions (e.g. financial approvals, SaaS consents, or executing supplied payloads) that strong auth does not block.
- T1684.001prevents — A.8.5's MFA, strong auth, log-on hardening, session termination and brute-force protections stop many impersonation vectors that rely on stolen or guessed credentials to substantiate a false identity, but the core social-engineering deception (persuasive language, spoofed sender, urgency) occurs outside any authentication step and is untouched.
- T1684.002prevents — A.8.5 mandates choosing and enforcing suitable/strong authentication techniques (including MFA, alternative factors, and rules-based additional checks) whose purpose is to substantiate claimed identities before granting access; this directly stops spoofed sender identities from successfully passing authentication in email environments (via DMARC/SPF/DKIM enforcement and related logon protections), with the bounded remainder being non-enforced or legacy paths (e.g., p=none policies or Direct Send abuse) that the clause's own guidance names as insufficient.
- T1689detects — A.8.5 explicitly requires logging of successful/unsuccessful log-on attempts, raising security events/alerts on potential breaches or excessive failures, and separate-channel notification of prior failed attempts, which surfaces many downgrade attempts that abuse legacy/weak auth modes or clear-text protocols during authentication flows; this is only a slice of the broad technique (e.g. non-auth PowerShell downgrades, boot manager changes, or non-logon network downgrades remain unseen).
- T1689prevents — A.8.5 mandates authentication strength proportionate to data classification plus explicit protections (MFA, no clear-text transmission, brute-force blocking, session termination) that stop downgrade-to-weak-authentication paths on the authentication surface itself; the named remainder is non-authentication downgrades (e.g. boot manager, PowerShell interpreter, protocol fallback outside the log-on procedure).
Prevented OWASP Web Top 10 (2025) risks (16)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A01mitigates — A.8.5's log-on hardening (brute-force protection, MFA, session termination, no cleartext creds) bounds the blast radius or blocks some exploitation paths of realized authorization failures (e.g. stolen sessions, weak credential replay), but does not address the core authorization-decision defects named in A01:2025 (path traversal, IDOR, missing function-level checks, CSRF).
- A04mitigates — A.8.5's MFA, strong auth, no-cleartext transmission and session termination requirements bound the blast radius or consequence of weak/misused crypto (especially transit exposure and session hijacking) without addressing the core absence/weakness/misuse of cryptography itself.
- A07mitigates — A.8.5 directly implements strong MFA, anti-brute-force, session termination, secure log-on flows, and credential-protection measures that bound the blast radius or success probability of the exact attacks named in A07 (credential stuffing, weak reset, session hijacking, brute force).
- A07prevents — A.8.5 directly mandates strong/multi-factor authentication techniques, log-on hardening (no info leakage, brute-force protection, no cleartext transmission, session termination), and MFA for critical systems, which squarely blocks the dominant authentication-bypass, credential-stuffing, weak-reset, and session-hijacking patterns named in A07:2025; residual gaps (e.g., implementation flaws in the chosen technique or non-covered edge cases) keep it from full.
- A09mitigates — A.8.5's logging of successful/unsuccessful log-on attempts, security-event raising on breach detection, and alerts (e.g. on repeated failures) directly reduce the undetected-incident consequence of missing or ineffective logging/alerting, but the clause's dominant focus is on authentication mechanisms themselves rather than comprehensive event coverage, log integrity, or non-authentication events.
- A10mitigates — A.8.5's log-on hardening (no info leaks before/during auth, brute-force protection, MFA, session termination, alerts on failures) bounds the blast radius or consequence of fail-open auth and error-path leaks in A10, but does not address logic-flaw error handling or inconsistent post-exception states.
- A10prevents — A.8.5's log-on procedure rules (a–e, g–j) directly block information leaks, brute-force, cleartext exposure and fail-open authentication paths that are core to the A10 class; residual logic-flaw error handling in application code and non-authentication exception paths remain untouched.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.