Capability ID | Capability Description | Category | Value | ATT&CK ID | ATT&CK Name | Notes |
---|---|---|---|---|---|---|
advanced_protection_program | Advanced Protection Program | protect | significant | T1556.001 | Domain Controller Authentication |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Integrating multi-factor authentication as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access, lateral movement, and collecting information.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1556.003 | Pluggable Authentication Modules |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Integrating multi-factor authentication as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access, lateral movement, and collecting information.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1556.004 | Network Device Authentication |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Integrating multi-factor authentication as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access, lateral movement, and collecting information.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1556.005 | Reversible Encryption |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Even in the event of compromised credentials, the lack of a security key would prevent an adversary from accessing the account. This leads to significant protection against the technique.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1556.007 | Hybrid Identity |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Even in the event of compromised credentials, the lack of a security key would prevent an adversary from accessing the account. This leads to significant protection against the technique.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1556.008 | Network Provider DLL |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Even in the event of compromised credentials, the lack of a security key would prevent an adversary from accessing the account. This leads to significant protection against the technique.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1556.009 | Conditional Access Policies |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Even in the event of compromised credentials, the lack of a security key would prevent an adversary from accessing the account. This leads to significant protection against the technique.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1021 | Remote Services |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Implementing MFA on remote service logons prevents adversaries from using valid accounts to access those services.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1078.002 | Domain Accounts |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Integrating multi-factor authentication (MFA) as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access, lateral movement, and collecting information.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1078.004 | Cloud Accounts |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Integrating multi-factor authentication (MFA) as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access, lateral movement, and collecting information.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1098 | Account Manipulation |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. This provides significant protection against unauthorized users from accessing and manipulating accounts to retain access.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1110 | Brute Force |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. This provides significant protection against Brute Force techniques attempting to gain access to accounts.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1110.001 | Password Guessing |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. This provides significant protection against Brute Force techniques attempting to gain access to accounts.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1110.002 | Password Cracking |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. This provides significant protection against Brute Force techniques attempting to gain access to accounts.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1110.003 | Password Spraying |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. This provides significant protection against Brute Force techniques attempting to gain access to accounts.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1110.004 | Credential Stuffing |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. This provides significant protection against Brute Force techniques attempting to gain access to accounts.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1114 | Email Collection |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Enabling MFA reduces the usefulness of usernames and passwords that may be collected via email since adversaries won't have the associated security keys to gain access.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1133 | External Remote Services |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Enabling MFA for remote service accounts can mitigate an adversary's ability to leverage stolen credentials since they won't have the respective security key to gain access.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1136 | Create Account |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Enabling Advanced Protection Program for all users at an organization can prevent adversaries from maintaining access via created accounts because any accounts they create won't have the required security keys for MFA.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1530 | Data from Cloud Storage |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Restricting access via MFA provides significant protection against adversaries accessing data objects from cloud storage.
References
|
advanced_protection_program | Advanced Protection Program | protect | significant | T1556 | Modify Authentication Process |
Comments
Advanced Protection Program enables the use of a security key for multi-factor authentication. Integrating multi-factor authentication as part of organizational policy can greatly reduce the risk of an adversary gaining control of valid credentials that may be used for additional tactics such as initial access, lateral movement, and collecting information.
References
|
Capability ID | Capability Name | Number of Mappings |
---|---|---|
advanced_protection_program | Advanced Protection Program | 21 |