FORENSIA

ATT&CK · T1134

Access Token Manipulation

Tactics: stealth, privilege-escalation

About

Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls. Windows uses access tokens to determine the ownership of a running process. A user can manipulate access tokens to make a running process appear as though it is the child of a different process or belongs to someone other than the user that started the process. When this occurs, the process also takes on the security context associated with the new token. An adversary can use built-in Windows API functions to copy access tokens from existing processes; this is known as token stealing. These token can then be applied to an existing process (i.e. Token Impersonation/Theft) or used to spawn a new process (i.e. Create Process with Token). An adversary must already be in a privileged user context (i.e. administrator) to steal a token. However, adversaries commonly use token stealing to elevate their security context from the administrator level to the SYSTEM level. An adversary can then use a token to authenticate to a remote system as the account for that token if the account has appropriate permissions on the remote system. Any standard user can use the <code>runas</code> command, and the Windows API functions, to create impersonation tokens; it does not require access to an administrator account. There are also other mechanisms, such as Active Directory fields, that can be used to modify access tokens.

Platforms: WindowsMITRE ATT&CK ↗

Used by actors

3 known groups

Software

19 malware/tools implement this

DuquSslMMPowerSploitHydraqEmpirePoshC2RyukSUNSPOTMegaCortexKillDiskAppleSeedCubaSliverGelsemiumHermeticWiperMafaldaBlackCatSagerunexQilin

Corpus indicators tagged with this technique

109 indicators in the corpus carry T1134.

IndicatorTypeFamilySevSrc
03e7a4065df354a99add76e8ba7dd37bhash803
c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926csha256801
b498256cb086a6962077cdd6d2f65327hashphishing802
b3e853eee14fb7948c6907888ee07139085ba9af4231c30e97ff6236b86ca024hash803
a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02sha256801
c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0sha256801
4c9061a07d667bf7dd6f597a43a8552af2f4277b7be06d6ea138abdb668d6a49hashphishing802
949acbe543fc244ffbc981ea169067da7c5792af3c3d19b2c31b3d7e19106880hashphishing802
49c827cf48efb122a9d6fd87b426482b7496ccd4a2dbca31ebbf6b2b80c98530sha256801
90bbfa9e7af176b85d110f4f1789cae6777fcb60813b047133c8f12caa344a17hash803
6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6acsha256801
7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8sha256801
59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347sha256802
17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4sha256802
4650f7dc1a2ddbb6d73bf5bfd1b69dd6b79e0cddhashphishing802
185b7a487316454da04e9cc0fe6eb370bb2955cf6096fe3e8c02c46f8989ba37hashphishing802
7d87a86dbd2379ef2516c99258137cd9c25ca19c48aeb096c5332c02fcbf16d0hashphishing802
87d4c8d022a298cefcb113040e69934d5be6a91chashphishing802
be31a63cad112723178289968ad6f93a576c5a7984099c42eec3521cdf6e5fc0hashphishing802
e83ff54e58f0b295a392c7fc39a7d0dehashphishing802
5bb5cffda4647940919a185df37aab2aef71ca3010a6c1d05bdcc8bc8fb3af3fsha256801
15278c52f4e0d8b5bbfe288a5e826ab2ebeaedb7fb85572940cf1263e384761fhash803
3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80esha256802
09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1sha256802
2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06asha256802
66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865sha256801
04e7a98fb3b7738cca42557c3e2d9906d04fa2f6hash803
1852120a84a328edd1995e633dfd2009867898a8e3f0b385e2490cf21c77a994hash803
3a8f6454927b8993aded75de0de2bd00hashphishing802
c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809sha256801

Showing the top 30 by severity of 109.