{"id":"T1556.007","name":"Hybrid Identity","url":"https://attack.mitre.org/techniques/T1556/007","tactics":["defense-impairment","persistence","credential-access"],"platforms":["IaaS","Identity Provider","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0293","stix_id":"x-mitre-detection-strategy--6b681059-99f7-46ff-bd36-96fd414074d4","name":"Detect Hybrid Identity Authentication Process Modification","url":"https://attack.mitre.org/detectionstrategies/DET0293","analytics":[{"id":"AN0814","stix_id":"x-mitre-analytic--344f0add-d372-4e0e-88c6-f48e6b424434","name":"Analytic 0814","description":"Detects injection or tampering of DLLs in hybrid identity agents (e.g., AzureADConnectAuthenticationAgentService), registry or configuration changes tied to PTA/AD FS, and anomalous LSASS or AD FS module loads correlated with authentication anomalies.","url":"https://attack.mitre.org/detectionstrategies/DET0293#AN0814","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=5136","data_component":"DC0066","data_component_name":"Active Directory Object Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"Anomalous logon without MFA enforcement","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"WatchedServices","description":"Hybrid identity services monitored for tampering, e.g., PTA agent, AD FS."},{"field":"TimeWindow","description":"Window correlating DLL/module load events with logon anomalies."}],"live":true,"detection_strategies":["DET0293"],"techniques":["T1556.007"]},{"id":"AN0815","stix_id":"x-mitre-analytic--e1063b92-9be0-4d25-9df5-bae4171c8153","name":"Analytic 0815","description":"Detects registration of new PTA agents, conditional access changes disabling hybrid MFA enforcement, or suspicious updates to AD FS token-signing configurations.","url":"https://attack.mitre.org/detectionstrategies/DET0293#AN0815","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:signinlogs","channel":"Register PTA Agent or Modify AD FS trust","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"azure-signinlogs"},{"name":"m365:unified","channel":"New agent registration by non-admin user","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"PrivilegedRoles","description":"Roles authorized to configure PTA/AD FS integrations."}],"live":true,"detection_strategies":["DET0293"],"techniques":["T1556.007"]},{"id":"AN0816","stix_id":"x-mitre-analytic--80e4f847-a149-423b-a179-cbcf4afd06b9","name":"Analytic 0816","description":"Detects API calls registering or updating hybrid identity connectors, modification of cloud-to-on-premises federation trust, and unusual token issuance logs.","url":"https://attack.mitre.org/detectionstrategies/DET0293#AN0816","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"UpdateFederationSettings or RegisterHybridConnector","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"MonitoredFederations","description":"Federation trusts and connectors relevant to hybrid identity setup."}],"live":true,"detection_strategies":["DET0293"],"techniques":["T1556.007"]},{"id":"AN0817","stix_id":"x-mitre-analytic--07b8a45e-6435-4c67-ac15-47db21c1d1b9","name":"Analytic 0817","description":"Detects tenant-wide authentication or conditional access changes that weaken hybrid identity enforcement, including disabling AD FS or bypassing hybrid MFA policies.","url":"https://attack.mitre.org/detectionstrategies/DET0293#AN0817","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Modify Federation Settings or Update Authentication Policy","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"PolicyScope","description":"Scope of authentication and federation policies to be monitored."}],"live":true,"detection_strategies":["DET0293"],"techniques":["T1556.007"]},{"id":"AN0818","stix_id":"x-mitre-analytic--bf166688-0c78-43a5-bb87-3159c1b86584","name":"Analytic 0818","description":"Detects suspicious changes to SAML/OAuth federation configurations, such as new signing certificates, altered endpoints, or claims issuance rules granting elevated privileges.","url":"https://attack.mitre.org/detectionstrategies/DET0293#AN0818","platforms":["SaaS"],"log_source_references":[{"name":"saas:okta","channel":"Federation configuration update or signing certificate change","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-okta"}],"mutable_elements":[{"field":"FederationEndpoints","description":"Federation/SAML endpoints monitored for modification."}],"live":true,"detection_strategies":["DET0293"],"techniques":["T1556.007"]}],"live":true,"version":"1.0","techniques":["T1556.007"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}