Name:Windows Access Token Manipulation Winlogon Duplicate Token Handle id:dda126d7-1d99-4f0b-b72a-4c14031f9398 version:10 date:None author:Teoderick Contreras, Splunk status:production type:Hunting Description:The following analytic detects a process requesting duplicate-handle and query-limited-information access to winlogon.exe.
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000). Data_source:
NOT SourceImage IN ( "C:\\Windows\\system32\\LogonUI.exe", "C:\\Windows\\system32\\lsass.exe", "C:\\Windows\\system32\\smss.exe", "C:\\Windows\\system32\\svchost.exe", "C:\\Windows\\system32\\wbem\\wmiprvse.exe" )
how_to_implement:To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. known_false_positives:It is possible legitimate applications will request access to winlogon, filter as needed. References: -https://docs.microsoft.com/en-us/windows/win32/api/handleapi/nf-handleapi-duplicatehandle -https://attack.mitre.org/techniques/T1134/001/ drilldown_searches:
: analytic_story:['Brute Ratel C4']