The most appropriate next step after identifying that an attacker manipulated authentication tokens to gain privileged access is to identify the specific MITRE ATT&CK technique(s) associated with this behavior and then explore its sub-techniques and related techniques. MITRE ATT&CK is a knowledge base of adversary tactics and techniques based on real-world observations. An attacker manipulating authentication tokens to gain privileged access directly relates to the 'T1539' technique, 'Steal Application Access Token', and potentially 'T1134.001', 'Token Impersonation/Theft', or 'T1134.002', 'Access Token Manipulation', depending on t....
Log in to view the answer