LoFP LoFP / t1556.006

t1556.006

TitleTags
aws administrators may disable mfa but it is highly unlikely for this event to occur without prior notice to the company
false positives may be generated by normal provisioning workflows for user device registration.
false positives may be generated by normal provisioning workflows that generate a password reset followed by a device registration.
false positives may be generated by users working out the geographic region where the organizations services or technology is hosted.
if a mfa reset or deactivated was performed by a system administrator.
if this was approved by system administrator.
legitimate use case may require for users to disable mfa. filter as needed.
legitimate use case may require for users to disable mfa. filter lightly and monitor for any unusual activity.
newly onboarded users who are registering an mfa method for the first time will also trigger this detection.