Capability ID | Capability Description | Category | Value | ATT&CK ID | ATT&CK Name | Notes |
---|---|---|---|---|---|---|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1098 | Account Manipulation |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. This provides significant protection against unauthorized users from accessing and manipulating accounts to retain access.
References
|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1110 | Brute Force |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. This provides significant protection against Brute Force techniques attempting to gain access to accounts.
References
|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1136 | Create Account |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Enabling Advanced Protection Program for all users at an organization can prevent adversaries from maintaining access via created accounts because any accounts they create won't have the required security keys for MFA.
References
|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1530 | Data from Cloud Storage Object |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Restricting access via MFA provides significant protection against adversaries accessing data objects from cloud storage.
References
|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1114 | Email Collection |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Enabling MFA reduces the usefulness of usernames and passwords that may be collected via email since adversaries won't have the associated security keys to gain access.
References
|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1133 | External Remote Services |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Enabling MFA for remote service accounts can mitigate an adversary's ability to leverage stolen credentials since they won't have the respective security key to gain access.
References
|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1556 | Modify Authentication Process |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Integrating multi-factor authentication as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access, lateral movement, and collecting information.
References
|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1021 | Remote Services |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Implementing MFA on remote service logons prevents adversaries from using valid accounts to access those services.
References
|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1078.002 | Domain Accounts |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Integrating multi-factor authentication (MFA) as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access, lateral movement, and collecting information.
References
|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1078.004 | Cloud Accounts |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Integrating multi-factor authentication (MFA) as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access, lateral movement, and collecting information.
References
|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1110.001 | Password Guessing |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. This provides significant protection against Brute Force techniques attempting to gain access to accounts.
References
|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1110.002 | Password Cracking |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. This provides significant protection against Brute Force techniques attempting to gain access to accounts.
References
|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1110.003 | Password Spraying |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. This provides significant protection against Brute Force techniques attempting to gain access to accounts.
References
|
advancedprotectionprogram | AdvancedProtectionProgram | protect | significant | T1110.004 | Credential Stuffing |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. This provides significant protection against Brute Force techniques attempting to gain access to accounts.
References
|
Capability ID | Capability Name | Number of Mappings |
---|---|---|
advancedprotectionprogram | AdvancedProtectionProgram | 14 |