Make and Impersonate Token

T1134.003

Sub-technique of T1134 Access Token Manipulation.View on attack.mitre.org

About this technique

Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls. For example, if an adversary has a username and password but the user is not logged onto the system the adversary can then create a logon session for the user using the `LogonUser` function. The function will return a copy of the new session's access token and the adversary can use `SetThreadToken` to assign the token to a thread.

This behavior is distinct from Token Impersonation/Theft in that this refers to creating a new user token instead of stealing or duplicating an existing one.

Detection rules4

Rules on DetectionCode tagged with T1134.003.

Sigma4

RuleLevelLog source
HackTool - SharpDPAPI Executionhighwindows / process_creation
HackTool - SharpImpersonation Executionhighwindows / process_creation
HackTool - Impersonate Executionmediumwindows / process_creation
Potentially Suspicious Explicit Credential Local Logonmediumwindows / NULL

Splunk0

No Splunk rules are mapped to this technique yet.

Groups2

Software3

Campaigns0

None recorded.

Procedure examples5

Groups2

Used byProcedure example
GroupBlackByte

BlackByte constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution.

GroupFIN13

FIN13 has utilized tools such as Incognito V2 for token manipulation and impersonation.

Software3

Used byProcedure example
MalwareCobalt Strike

Cobalt Strike can make tokens from known credentials.

MalwareMafalda

Mafalda can create a token for a different user.

ToolSILENTTRINITY

SILENTTRINITY can make tokens from known credentials.

References1

  1. LogonUserW function Open source
    Microsoft. (2023, March 10). LogonUserW function (winbase.h). Retrieved January 8, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.