ATT&CK · T1134.003 · sub-technique
Make and Impersonate Token
Tactics: stealth, privilege-escalation
About
Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls. For example, if an adversary has a username and password but the user is not logged onto the system the adversary can then create a logon session for the user using the `LogonUser` function. The function will return a copy of the new session's access token and the adversary can use `SetThreadToken` to assign the token to a thread. This behavior is distinct from Token Impersonation/Theft in that this refers to creating a new user token instead of stealing or duplicating an existing one.
Used by actors
2 known groups
Software
3 malware/tools implement this
Corpus indicators tagged with this technique
11 indicators in the corpus carry T1134.003.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| f61fbfb7aa1cd5dc8f70b055b51563e2 | md5 | — | 76 | 1 |
| 9f5f2f0fb0a7f5aa9f16b9a7b6dad89f | md5 | — | 76 | 1 |
| 28cb7b261f4eb97e8a4b3b0d32f8def1 | md5 | — | 76 | 1 |
| 1ab58838e5790efb22f2d35ab98c0b7d | md5 | — | 76 | 1 |
| 22aaeb4946ba6d2f2e27feb7dbb295de | md5 | — | 76 | 1 |
| 3432dd9ac0df80ef86eb80bd080f839b | md5 | — | 76 | 1 |
| 3d3a621f852c42d97fd7260681e42508 | md5 | — | 76 | 1 |
| a7d7d6c4c3f227f7117261c63b9e23a9 | md5 | — | 76 | 1 |
| bae82a15d1dbfb024617b9b56a8e5f66 | md5 | — | 76 | 1 |
| f169d6d172dfb775895a5e2b1540c854 | md5 | — | 76 | 1 |
| 2fuserinfo.email | domain | — | 65 | 1 |