diff --git a/atomics/T1112/T1112.yaml b/atomics/T1112/T1112.yaml index 8a87b367..bd66a7c7 100644 --- a/atomics/T1112/T1112.yaml +++ b/atomics/T1112/T1112.yaml @@ -947,6 +947,7 @@ atomic_tests: reg add "HKLM\SOFTWARE\Policies\Microsoft\SecondaryAuthenticationFactor" /v "AllowSecondaryAuthenticationDevice" /t REG_DWORD /d 1 /f name: command_prompt - name: Activities To Disable Microsoft [FIDO Aka Fast IDentity Online] Authentication Detected By Modified Registry Value. + auto_generated_guid: ffeddced-bb9f-49c6-97f0-3d07a509bf94 description: | Detect the Microsoft FIDO authentication disable activities that adversary attempt to gains access to login credentials (e.g., passwords), they may be able to impersonate the user and access sensitive accounts or data and also increases the risk of falling victim to phishing attacks. See the related article (https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.FidoAuthentication::AllowFidoDeviceSignon). diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index 0e57cb52..b478b326 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -1521,3 +1521,4 @@ a0c1725f-abcd-40d6-baac-020f3cf94ecd 2871ed59-3837-4a52-9107-99500ebc87cb 2a3c7035-d14f-467a-af94-933e49fe6786 ae56083f-28d0-417d-84da-df4242da1f7c +ffeddced-bb9f-49c6-97f0-3d07a509bf94