Skip to content

Add T1556.006 Multi-Factor Authentication atomic tests - #3379

Open
einlamye wants to merge 6 commits into
redcanaryco:masterfrom
einlamye:atomic-t1556-mfa
Open

einlamye wants to merge 6 commits into
redcanaryco:masterfrom
einlamye:atomic-t1556-mfa

Conversation

@einlamye

@einlamye einlamye commented Jul 3, 2026

Copy link
Copy Markdown

Details:
Adds two atomic tests for T1556.006 (Multi-Factor Authentication).

  1. Disable MFA by Blackholing Provider Domain via Windows hosts File — the documented ATT&CK
    example: null-routes the MFA provider hostname in %windir%\System32\drivers\etc\hosts.
  2. Disable MFA by Blackholing Provider Domain via /etc/hosts — Linux/macOS equivalent.
    Both keyed on a # T1556.006 marker comment for clean, reversible cleanup.

Testing: pydantic-model validated; elevation_required: true set where sudo is used.

Associated Issues: (none)

Comment thread atomics/T1556.006/T1556.006.yaml Outdated
display_name: 'Modify Authentication Process: Multi-Factor Authentication'
atomic_tests:
- name: Disable MFA by Blackholing Provider Domain via Windows hosts File
auto_generated_guid: 9f5deb8d-f3cf-47df-899c-0de1958980c6

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@einlamye - can we remove this auto_generated_guid

This gets auto_generated_guid

also, remove the .MD file - that also gets auto generated!

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes do as you wish tanks for your review 🙏

Deleted as said in the comment
Removed auto generated field as said in the comment

@einlamye einlamye left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just did the requested changes:

  1. Remove the md file
  2. Remove the auto generated field

@patel-bhavin

Copy link
Copy Markdown
Collaborator

Thank you! Can you share execution and cleanup commands of this atomic via Invoke, this would help us with reviewing and merging of the atomic!

Neat atomic !

@einlamye

Copy link
Copy Markdown
Author

Thanks! Here are the Invoke-AtomicRedTeam commands for both atomics.

Windows:

Invoke-AtomicTest T1556.006 -TestNames "Disable MFA by Blackholing Provider Domain via Windows hosts File" -InputArgs @{"mfa_domain"="api-xxxxxxxx.duosecurity.com"}

Invoke-AtomicTest T1556.006 -TestNames "Disable MFA by Blackholing Provider Domain via Windows hosts File" -InputArgs @{"mfa_domain"="api-xxxxxxxx.duosecurity.com"} -Cleanup

Linux/macOS:

Invoke-AtomicTest T1556.006 -TestNames "Disable MFA by Blackholing Provider Domain via /etc/hosts" -InputArgs @{"mfa_domain"="api-xxxxxxxx.duosecurity.com"}

Invoke-AtomicTest T1556.006 -TestNames "Disable MFA by Blackholing Provider Domain via /etc/hosts" -InputArgs @{"mfa_domain"="api-xxxxxxxx.duosecurity.com"} -Cleanup

The mfa_domain input can be replaced with the MFA provider hostname used in the test environment.

Both atomics require elevated privileges, as reflected by elevation_required: true. The cleanup removes the # T1556.006 entries added by the corresponding test.

Thanks again for taking a look.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

This PR is stale because it has been open 45 days with no activity. Remove stale label or comment or this will be closed in 10 days.

@github-actions github-actions Bot added the Stale label Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants