EXPLORE
← Back to Explore
T1134

Access Token Manipulation

Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls. Windows uses access tokens to determine the ownership of a running process. A user can manipulate access tokens to make a running process appear as though it is the child of a different process or belongs to someone other than the user that started the process. When this occurs, the process also takes on the security context associated with the new toke...

Windows
28
Detections
4
Sources
3
Threat Actors

BY SOURCE

20elastic3kql3splunk_escu2sigma

PROCEDURES (24)

General Monitoring2 detections

Auto-extracted: 2 detections for general monitoring

Credential2 detections

Auto-extracted: 2 detections for credential

Impersonat2 detections

Auto-extracted: 2 detections for impersonat

Service2 detections

Auto-extracted: 2 detections for service

Api1 detections

Auto-extracted: 1 detections for api

Named Pipe1 detections

Auto-extracted: 1 detections for named pipe

Named Pipe1 detections

Auto-extracted: 1 detections for named pipe

Parent Process1 detections

Auto-extracted: 1 detections for parent process

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Credential1 detections

Auto-extracted: 1 detections for credential

Service1 detections

Auto-extracted: 1 detections for service

Process Creation Monitoring1 detections

Auto-extracted: 1 detections for process creation monitoring

Unusual1 detections

Auto-extracted: 1 detections for unusual

Script Execution Monitoring1 detections

Auto-extracted: 1 detections for script execution monitoring

Network Connection Monitoring1 detections

Auto-extracted: 1 detections for network connection monitoring

Unusual1 detections

Auto-extracted: 1 detections for unusual

Privilege1 detections

Auto-extracted: 1 detections for privilege

Unusual1 detections

Auto-extracted: 1 detections for unusual

Lateral1 detections

Auto-extracted: 1 detections for lateral

Parent Process1 detections

Auto-extracted: 1 detections for parent process

Lateral1 detections

Auto-extracted: 1 detections for lateral

Bypass1 detections

Auto-extracted: 1 detections for bypass

Masquerad1 detections

Auto-extracted: 1 detections for masquerad

Inject1 detections

Auto-extracted: 1 detections for inject

DETECTIONS (28)

*Detection Title*
kql
All BlackCat/ALPHV Ransomware IOCs with one KQL query
kql
Credential Manipulation - Detected - Elastic Endgame
elastichigh
Credential Manipulation - Prevented - Elastic Endgame
elasticmedium
First Time Seen NewCredentials Logon Process
elasticmedium
HackTool - NoFilter Execution
sigmahigh
Interactive Logon by an Unusual Process
elastichigh
Kubernetes API Request Impersonating Privileged Identity
elastichigh
Parent Process PID Spoofing
elastichigh
Permission Theft - Detected - Elastic Endgame
elastichigh
Permission Theft - Prevented - Elastic Endgame
elasticmedium
Potential PowerShell HackTool Script by Function Names
elasticmedium
PowerShell Script with Token Impersonation Capabilities
elasticmedium
Privilege Escalation via Named Pipe Impersonation
elastichigh
Privilege Escalation via Rogue Named Pipe Impersonation
elastichigh
Privileges Elevation via Parent Process PID Spoofing
elastichigh
Process Created with a Duplicated Token
elasticmedium
Process Created with an Elevated Token
elastichigh
Process Creation via Secondary Logon
elasticmedium
Process Primary Token Elevated to SeDebugPrivilege
kql
SeDebugPrivilege Enabled by a Suspicious Process
elasticmedium
Spike in Special Privilege Use Events
elasticlow
Suspicious SeIncreaseBasePriorityPrivilege Use
elastichigh
Suspicious SYSTEM User Process Creation
sigmahigh
Unusual Parent-Child Relationship
elasticmedium
Windows Privilege Escalation Suspicious Process Elevation
splunk_escu
Windows Privilege Escalation System Process Without System Parent
splunk_escu
Windows Privilege Escalation User Process Spawn System Process
splunk_escu