Sub-technique of T1134 Access Token Manipulation.View on attack.mitre.org
Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread.
An adversary may perform Token Impersonation/Theft when they have a specific, existing process they want to assign the duplicated token to. For example, this may be useful for when the target user has a non-network logon session on the system.
When an adversary would instead use a duplicated token to create a new process rather than attaching to an existing process, they can additionally Create Process with Token using `CreateProcessWithTokenW` or `CreateProcessAsUserW`. Token Impersonation/Theft is also distinct from Make and Impersonate Token in that it refers to duplicating an existing token, rather than creating a new one.
Rules on DetectionCode tagged with T1134.001.
| Rule | Level | Log source |
|---|---|---|
| HackTool - Koh Default Named Pipe | critical | windows / pipe_created |
| HackTool - NoFilter Execution | high | windows / NULL |
| HackTool - SharpDPAPI Execution | high | windows / process_creation |
| HackTool - SharpImpersonation Execution | high | windows / process_creation |
| Meterpreter or Cobalt Strike Getsystem Service Installation - Security | high | windows / NULL |
| Meterpreter or Cobalt Strike Getsystem Service Installation - System | high | windows / NULL |
| Potential Meterpreter/CobaltStrike Activity | high | windows / process_creation |
| HackTool - Impersonate Execution | medium | windows / process_creation |
| Potential Access Token Abuse | medium | windows / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Runas Execution in CommandLine | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Access Token Manipulation Winlogon Duplicate Token Handle | Hunting | NULL | Sysmon EventID 10 |
| Windows Access Token Winlogon Duplicate Handle In Uncommon Path | Anomaly | NULL | Sysmon EventID 10 |
| Windows Handle Duplication in Known UAC-Bypass Binaries | Anomaly | NULL | Sysmon EventID 10 |
| Windows Wermgr Spawning System Integrity Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 has used CVE-2015-1701 to access the SYSTEM token and copy it into the current process as part of privilege escalation. |
| GroupFIN8 | FIN8 has used a malicious framework designed to impersonate the lsass.exe/vmtoolsd.exe token. |
| Used by | Procedure example |
|---|---|
| MalwareAria-body | Aria-body has the ability to duplicate a token from ntprint.exe. |
| MalwareBADHATCH | BADHATCH can impersonate a `lsass.exe` or `vmtoolsd.exe` token. |
| MalwareBitPaymer | BitPaymer can use the tokens of users to create processes on infected systems. |
| MalwareCobalt Strike | Cobalt Strike can steal access tokens from exiting processes. |
| MalwareEmotet | Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed. |
| MalwareFinFisher | FinFisher uses token manipulation with NtFilterToken as part of UAC bypass. |
| MalwareFooder | Fooder has used the `DuplicateTokenEx` API to duplicate the token of a specified process, and `CreateProcessAsUserA` to execute its payload. |
| MalwareHavoc | Havoc has a module capable of token impersonation. |
| Used by | Procedure example |
|---|---|
| CampaignHomeLand Justice | During HomeLand Justice, threat actors used custom tooling to acquire tokens using `ImpersonateLoggedOnUser/SetThreadToken`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.