{"id":"T1556.005","name":"Reversible Encryption","url":"https://attack.mitre.org/techniques/T1556/005","tactics":["defense-impairment","persistence","credential-access"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0589","stix_id":"x-mitre-detection-strategy--b865c4e8-f3de-471e-846c-2290b6d52da9","name":"Detect Modification of Authentication Process via Reversible Encryption","url":"https://attack.mitre.org/detectionstrategies/DET0589","analytics":[{"id":"AN1621","stix_id":"x-mitre-analytic--105ca36e-c3e0-48c4-ada3-7f8c4aa4430f","name":"Analytic 1621","description":"Detects enabling of reversible password encryption in Active Directory or Group Policy, suspicious PowerShell commands modifying AD user properties, and unusual account configuration changes correlated with policy modifications. Multi-event correlation links Group Policy edits, PowerShell command execution, and user account property changes to identify tampering with authentication encryption settings.","url":"https://attack.mitre.org/detectionstrategies/DET0589#AN1621","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4739","data_component":"DC0066","data_component_name":"Active Directory Object Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"}],"mutable_elements":[{"field":"MonitoredOUs","description":"Scope of Organizational Units where reversible encryption property monitoring is enabled."},{"field":"TimeWindow","description":"Time window in which to correlate Group Policy modification and subsequent user property changes."},{"field":"SuspiciousCmdletList","description":"List of PowerShell cmdlets to monitor for account configuration changes."}],"live":true,"detection_strategies":["DET0589"],"techniques":["T1556.005"]}],"live":true,"version":"1.0","techniques":["T1556.005"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}