{"id":"T1621","name":"Multi-Factor Authentication Request Generation","url":"https://attack.mitre.org/techniques/T1621","tactics":["credential-access"],"platforms":["Windows","Linux","macOS","IaaS","SaaS","Office Suite","Identity Provider"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0160","stix_id":"x-mitre-detection-strategy--5dab1bc7-89e2-4fe4-ae30-40b550d0daf4","name":"Detection Strategy for Multi-Factor Authentication Request Generation (T1621)","url":"https://attack.mitre.org/detectionstrategies/DET0160","analytics":[{"id":"AN0449","stix_id":"x-mitre-analytic--f51edea3-e0e8-4090-8e81-a01c3394ba53","name":"Analytic 0449","description":"Monitor for excessive or anomalous MFA push notifications or token requests, especially when login attempts originate from unusual IPs or geolocations and do not correspond to legitimate user-initiated sessions.","url":"https://attack.mitre.org/detectionstrategies/DET0160#AN0449","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:signinlogs","channel":"Multiple MFA challenge requests without successful primary login","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"azure-signinlogs"},{"name":"NSM:Connections","channel":"PushNotificationSent","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"nsm-connections"}],"mutable_elements":[{"field":"TimeWindow","description":"Threshold of MFA prompts per user within a short time period"},{"field":"GeoIPAllowList","description":"Expected login locations for workforce; deviations can be tuned"}],"live":true,"detection_strategies":["DET0160"],"techniques":["T1621"]},{"id":"AN0450","stix_id":"x-mitre-analytic--824db63f-2a2c-4e3e-8e7d-49110cc63173","name":"Analytic 0450","description":"Detect abnormal MFA activity within cloud service provider logs, such as repeated generation of MFA challenges for the same user session or mismatched MFA device and login origin.","url":"https://attack.mitre.org/detectionstrategies/DET0160#AN0450","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"AssumeRole or ConsoleLogin with repeated MFA failures followed by repeated MFA requests","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"FailedLoginThreshold","description":"Number of failed logins before raising detection"}],"live":true,"detection_strategies":["DET0160"],"techniques":["T1621"]},{"id":"AN0451","stix_id":"x-mitre-analytic--2c0df764-d9bd-4a91-808a-aa13df13511a","name":"Analytic 0451","description":"Detect repeated failed login events followed by MFA challenges triggered in rapid succession, especially if originating from service accounts or anomalous IP addresses.","url":"https://attack.mitre.org/detectionstrategies/DET0160#AN0451","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4625","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"ServiceAccountExclusion","description":"Exclude specific accounts where automated MFA requests are legitimate"}],"live":true,"detection_strategies":["DET0160"],"techniques":["T1621"]},{"id":"AN0452","stix_id":"x-mitre-analytic--e36b2d32-05a8-4bcf-b7cf-58dc3ad4c0d3","name":"Analytic 0452","description":"Monitor PAM and syslog entries for unusual frequency of login attempts that trigger MFA prompts, particularly when MFA challenges do not match expected user behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0160#AN0452","platforms":["Linux"],"log_source_references":[{"name":"auditd:AUTH","channel":"pam_unix or pam_google_authenticator invoked repeatedly within short interval","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"auditd-auth"}],"mutable_elements":[{"field":"AuthRetryThreshold","description":"Number of retries per user allowed before detection is triggered"}],"live":true,"detection_strategies":["DET0160"],"techniques":["T1621"]},{"id":"AN0453","stix_id":"x-mitre-analytic--e96b0210-f7d5-43ac-bf73-893f243f6015","name":"Analytic 0453","description":"Detect anomalous OAuth or SSO logins that repeatedly generate MFA challenges, particularly where MFA approvals are denied or timed out by the user.","url":"https://attack.mitre.org/detectionstrategies/DET0160#AN0453","platforms":["SaaS"],"log_source_references":[{"name":"saas:okta","channel":"MFAChallengeIssued","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-okta"}],"mutable_elements":[{"field":"MFAProvider","description":"Identify which MFA service provider logs are in use (Okta, Duo, Microsoft Authenticator)"}],"live":true,"detection_strategies":["DET0160"],"techniques":["T1621"]},{"id":"AN0454","stix_id":"x-mitre-analytic--801a3652-8772-4b69-8a13-d870be653ef0","name":"Analytic 0454","description":"Detect user account logon attempts that trigger multiple MFA challenges through enterprise identity integrations, especially if MFA push requests are generated without successful interactive login.","url":"https://attack.mitre.org/detectionstrategies/DET0160#AN0454","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"authd generating multiple MFA token requests","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"DeviceEnrollmentStatus","description":"Exclude unmanaged macOS devices that use different MFA providers"}],"live":true,"detection_strategies":["DET0160"],"techniques":["T1621"]}],"live":true,"version":"1.0","techniques":["T1621"]}],"sigma_rules":[{"id":"5496ff55-42ec-4369-81cb-00f417029e25","title":"Multifactor Authentication Interrupted","author":"AlertIQ","status":"test","level":"medium","date":"2021-10-10","modified":"2022-12-18","description":"Identifies user login with multifactor authentication failures, which might be an indication an attacker has the password for the account but can't pass the MFA challenge.","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-accounts"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1078.004","attack.t1110","attack.t1621"],"path":"rules/cloud/azure/signin_logs/azure_mfa_interrupted.yml","techniques":["T1078.004","T1110","T1621"],"cves":[]},{"id":"e40f4962-b02b-4192-9bfe-245f7ece1f99","title":"Multifactor Authentication Denied","author":"AlertIQ","status":"test","level":"medium","date":"2022-03-24","modified":null,"description":"User has indicated they haven't instigated the MFA prompt and could indicate an attacker has the password for the account.","references":["https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1078.004","attack.t1110","attack.t1621"],"path":"rules/cloud/azure/signin_logs/azure_mfa_denies.yml","techniques":["T1078.004","T1110","T1621"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}