Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/M1032
MITRE ATT&CK Mitigation

M1032: Multi-factor Authentication

ShareXLinkedInRedditHN

Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include: - *Something you know*: Passwords, PINs. - *Something you have*: Physical tokens, smartphone authenticator apps. - *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans. Implementing MFA across all critical systems and services ensures robust protection against account takeover and unauthorized access. This mitigation can be implemented through the following measures: Identity and Access Management (IAM): - Use IAM solutions like Azure Active Directory, Okta, or AWS IAM to enforce MFA policies for all user logins, especially for privileged roles. - Enable conditional access policies to enforce MFA for risky sign-ins (e.g., unfamiliar devices, geolocations). - Enable Conditional Access policies to only allow logins from trusted devices, such as those enrolled in Intune or joined via Hybrid/Entra. Authentication Tools and Methods: - Use authenticator applications such as Google Authenticator, Microsoft Authenticator, or Authy for time-based one-time passwords (TOTP). - Deploy hardware-based tokens like YubiKey, RSA SecurID, or smart cards for additional security. - Enforce biometric authentication for compatible devices and applications. Secure Legacy Systems: - Integrate MFA solutions with older systems using third-party tools like Duo Security or Thales SafeNet. - Enable RADIUS/NPS servers to facilitate MFA for VPNs, RDP, and other network logins. Monitoring and Alerting: - Use SIEM tools to monitor failed MFA attempts, login anomalies, or brute-force attempts against MFA systems. - Implement alerts for suspicious MFA activities, such as repeated failed codes or new device registrations. Training and Policy Enforcement: - Educate employees on the importance of MFA and secure authenticator usage. - Enforce policies that require MFA on all critical systems, especially for remote access, privileged accounts, and cloud applications.

▪Techniques addressed (48)

T1098.001Additional Cloud CredentialsT1040Network SniffingT1136.001Local AccountT1669Wi-Fi NetworksT1556.003Pluggable Authentication ModulesT1556Modify Authentication ProcessT1213Data from Information RepositoriesT1599Network Boundary BridgingT1114Email CollectionT1621Multi-Factor Authentication Request GenerationT1078.001Default AccountsT1601Modify System ImageT1078.002Domain AccountsT1136.002Domain AccountT1136.003Cloud AccountT1078.003Local AccountsT1098.005Device RegistrationT1110.003Password SprayingT1078.004Cloud AccountsT1601.002Downgrade System ImageT1098Account ManipulationT1556.007Hybrid IdentityT1021.004SSHT1539Steal Web Session CookieT1599.001Network Address Translation TraversalT1098.003Additional Cloud RolesT1110.001Password GuessingT1114.002Remote Email CollectionT1199Trusted RelationshipT1021.001Remote Desktop ProtocolT1078Valid AccountsT1136Create AccountT1556.001Domain Controller AuthenticationT1485Data DestructionT1098.006Additional Container Cluster RolesT1021.007Cloud ServicesT1072Software Deployment ToolsT1110Brute ForceT1110.004Credential StuffingT1110.002Password CrackingT1021Remote ServicesT1133External Remote ServicesT1098.002Additional Email Delegate PermissionsT1556.006Multi-Factor AuthenticationT1530Data from Cloud StorageT1601.001Patch System ImageT1213.003Code RepositoriesT1556.004Network Device Authentication

▪Reference

M1032on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.