Cisco Duo MFA Success Triggered by Admin-Assigned Bypass Code

Alert on Duo successful MFA logins that are attributed to bypass-user codes.

FreeReviewedSigma · Medium · v4
Product
cisco
Service
duo
Author
Nikita Khalimonenkov (SigmaHQ), DRL 1.1
Published
2024-04-17
Updated
2026-07-31

What it detects

This rule flags successful Duo MFA authentication events where the authentication reason indicates use of a bypass code for the user. Attackers or insiders could leverage bypass codes to complete MFA without the usual enrolled device flow, so correlating these successes helps identify potentially unauthorized access. The detection relies on Cisco Duo authentication telemetry fields indicating both the authentication event type and the bypass-code reason (e.g., bypass_user).

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.