FORENSIA

ATT&CK · T1134.002 · sub-technique

Create Process with Token

Tactics: stealth, privilege-escalation

About

Adversaries may create a new process with an existing token to escalate privileges and bypass access controls. Processes can be created with the token and resulting security context of another user using features such as <code>CreateProcessWithTokenW</code> and <code>runas</code>. Creating processes with a token not associated with the current user may require the credentials of the target user, specific privileges to impersonate that user, or access to the token to be used. For example, the token could be duplicated via Token Impersonation/Theft or created via Make and Impersonate Token before being used to create a process. While this technique is distinct from Token Impersonation/Theft, the techniques can be used in conjunction where a token is duplicated and then used to create a new process.

Used by actors

2 known groups

Software

11 malware/tools implement this

BankshotAzorultKONNIEmpirePoshC2ZxShellAria-bodyREvilPipeMonWhisperGateTONESHELL

Corpus indicators tagged with this technique

40 indicators in the corpus carry T1134.002.

IndicatorTypeFamilySevSrc
91a15554ec9e49c00c5ca301f276bd79d346968651d54204743a08a3ca8a5067hashphishing802
a49155df50963d2412534090bbd967749268bd013881ddb81d78b87f91cdc15bhashphishing802
6c6cbed6aad96564ed87094785be07a1hashphishing802
55d6238b01a177e25eb7d53c943f3abea64ec073hashphishing802
61e9d76f07334843df561fe4bac449fb6fdaed5e5eb91480bded225f3d265c5fhashphishing802
50ffce607867d8fa8eaf6ef5cd25a3c0e7e4415e881b9e55c04a67bcddb74fdfsha256supply_chain801
c8075bbff748096e1c6a1ea0aa67bb6762fdd7551427a12425b35b94c1f1ecf2sha256supply_chain801
f6669bd504ce6b0e303be7ee47f2ebbc062989c88c41f0a3f436044a24869798sha256supply_chain801
f34f550147c2792c1ff2a003d15be89e5573f0896c5aa6126068baa4621ef416hashphishing802
ee6330870087f66a237a7f7c115b65beb042299f12eae1e9004e016686d0c387hashphishing802
bc83817c6d2bf8df1d58eac946a12b5e2566b2ffe15cf96f37c711c4b755512bhashphishing802
bc090d75f51c293d916c40d4b21094faaec191a42d97448c92d264875bf1f17bhashphishing802
197f11a7b0003aa7da58a3302cfa2a96a670de91d39ddebc7a51ac1d9404a7e6hashphishing802
35af2cf5494181920b8624c7b719d39590e2a5ff5eaa1a2fa1ba86b2b5aa9b43hashphishing802
7f80add94ee8107a79c87a9b4ccbd33e39eccd1596748a5b88629dd6ac11b86dhashphishing802
164e322d6fbc62e254d73583acd7f39444c884d3f5e6a5d27db143fc25bc88b3sha256supply_chain801
17832aa629524ef6e8d8d6e9b6b902a8d324b559e3c36dbd0e221ab1690be871sha256supply_chain801
282b9bc318ad1234cbd1b86424b784299b8be31545802a7c6b751166b814b990sha256supply_chain801
965e3d19c89f12ef730120b84d9ee38755841447sha1supply_chain781
2890d90edfc08fb4cfafe0d5fa2a9fb6800dedf5sha1supply_chain781
71c6cd37ddc0e5899174c72eefee8b224fd1f4bbsha1supply_chain781
7b1919c35da92cf5fd2583783dc9364fd11b69d2sha1supply_chain781
8e162d4fc8c5c74e16bfb4346f893cc7a71c2476sha1supply_chain781
208166120775a11cb6680139ea0f3372md5supply_chain761
4c1bdb2b045debf5b25e5be540ef99f0md5supply_chain761
c2875e2f45e5f1dfa04463de53b3fa5amd5supply_chain761
c5207f87b9103634b4db6f120eb6172amd5supply_chain761
f189c338a5f2bc3cce06cee37c0b7522md5supply_chain761
http://43.160.202.246:8053url755
http://nvidiadriver.net/verv1432/winpatch-xd7d.winurlsupply_chain751

Showing the top 30 by severity of 40.