Sub-technique of T1134 Access Token Manipulation.View on attack.mitre.org
Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls. For example, if an adversary has a username and password but the user is not logged onto the system the adversary can then create a logon session for the user using the `LogonUser` function. The function will return a copy of the new session's access token and the adversary can use `SetThreadToken` to assign the token to a thread.
This behavior is distinct from Token Impersonation/Theft in that this refers to creating a new user token instead of stealing or duplicating an existing one.
Rules on DetectionCode tagged with T1134.003.
| Rule | Level | Log source |
|---|---|---|
| HackTool - SharpDPAPI Execution | high | windows / process_creation |
| HackTool - SharpImpersonation Execution | high | windows / process_creation |
| HackTool - Impersonate Execution | medium | windows / process_creation |
| Potentially Suspicious Explicit Credential Local Logon | medium | windows / NULL |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupBlackByte | BlackByte constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution. |
| GroupFIN13 | FIN13 has utilized tools such as Incognito V2 for token manipulation and impersonation. |
| Used by | Procedure example |
|---|---|
| MalwareCobalt Strike | Cobalt Strike can make tokens from known credentials. |
| MalwareMafalda | Mafalda can create a token for a different user. |
| ToolSILENTTRINITY | SILENTTRINITY can make tokens from known credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.