Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/M1032
MITRE ATT&CK Mitigation

M1032: Multi-factor Authentication

ShareXLinkedInRedditHN

Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include: - *Something you know*: Passwords, PINs. - *Something you have*: Physical tokens, smartphone authenticator apps. - *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans. Implementing MFA across all critical systems and services ensures robust protection against account takeover and unauthorized access. This mitigation can be implemented through the following measures: Identity and Access Management (IAM): - Use IAM solutions like Azure Active Directory, Okta, or AWS IAM to enforce MFA policies for all user logins, especially for privileged roles. - Enable conditional access policies to enforce MFA for risky sign-ins (e.g., unfamiliar devices, geolocations). - Enable Conditional Access policies to only allow logins from trusted devices, such as those enrolled in Intune or joined via Hybrid/Entra. Authentication Tools and Methods: - Use authenticator applications such as Google Authenticator, Microsoft Authenticator, or Authy for time-based one-time passwords (TOTP). - Deploy hardware-based tokens like YubiKey, RSA SecurID, or smart cards for additional security. - Enforce biometric authentication for compatible devices and applications. Secure Legacy Systems: - Integrate MFA solutions with older systems using third-party tools like Duo Security or Thales SafeNet. - Enable RADIUS/NPS servers to facilitate MFA for VPNs, RDP, and other network logins. Monitoring and Alerting: - Use SIEM tools to monitor failed MFA attempts, login anomalies, or brute-force attempts against MFA systems. - Implement alerts for suspicious MFA activities, such as repeated failed codes or new device registrations. Training and Policy Enforcement: - Educate employees on the importance of MFA and secure authenticator usage. - Enforce policies that require MFA on all critical systems, especially for remote access, privileged accounts, and cloud applications.

▪Techniques addressed (48)

T1098.001Additional Cloud CredentialsT1040Network SniffingT1136.001Local Account

▪Reference

M1032on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

T1669Wi-Fi Networks
T1556.003Pluggable Authentication Modules
T1556Modify Authentication Process
T1213Data from Information Repositories
T1599Network Boundary Bridging
T1114Email Collection
T1621Multi-Factor Authentication Request Generation
T1078.001Default Accounts
T1601Modify System Image
T1078.002Domain Accounts
T1136.002Domain Account
T1136.003Cloud Account
T1078.003Local Accounts
T1098.005Device Registration
T1110.003Password Spraying
T1078.004Cloud Accounts
T1601.002Downgrade System Image
T1098Account Manipulation
T1556.007Hybrid Identity
T1021.004SSH
T1539Steal Web Session Cookie
T1599.001Network Address Translation Traversal
T1098.003Additional Cloud Roles
T1110.001Password Guessing
T1114.002Remote Email Collection
T1199Trusted Relationship
T1021.001Remote Desktop Protocol
T1078Valid Accounts
T1136Create Account
T1556.001Domain Controller Authentication
T1485Data Destruction
T1098.006Additional Container Cluster Roles
T1021.007Cloud Services
T1072Software Deployment Tools
T1110Brute Force
T1110.004Credential Stuffing
T1110.002Password Cracking
T1021Remote Services
T1133External Remote Services
T1098.002Additional Email Delegate Permissions
T1556.006Multi-Factor Authentication
T1530Data from Cloud Storage
T1601.001Patch System Image
T1213.003Code Repositories
T1556.004Network Device Authentication