EXPLORE
← Back to Explore
T1134

Access Token Manipulation

Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls. Windows uses access tokens to determine the ownership of a running process. A user can manipulate access tokens to make a running process appear as though it is the child of a different process or belongs to someone other than the user that started the process. When this occurs, the process also takes on the security context associated with the new toke...

Windows
31
Detections
4
Sources
3
Threat Actors

BY SOURCE

21elastic4sigma3kql3splunk_escu

PROCEDURES (24)

Bypass3 detections

Auto-extracted: 3 detections for bypass

Suspicious2 detections

Auto-extracted: 2 detections for suspicious

General Monitoring2 detections

Auto-extracted: 2 detections for general monitoring

Credential2 detections

Auto-extracted: 2 detections for credential

Service2 detections

Auto-extracted: 2 detections for service

Persist1 detections

Auto-extracted: 1 detections for persist

Named Pipe1 detections

Auto-extracted: 1 detections for named pipe

Unusual1 detections

Auto-extracted: 1 detections for unusual

Parent Process1 detections

Auto-extracted: 1 detections for parent process

Powershell1 detections

Auto-extracted: 1 detections for powershell

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Script Execution Monitoring1 detections

Auto-extracted: 1 detections for script execution monitoring

Unusual1 detections

Auto-extracted: 1 detections for unusual

Lateral1 detections

Auto-extracted: 1 detections for lateral

Privilege1 detections

Auto-extracted: 1 detections for privilege

Unusual1 detections

Auto-extracted: 1 detections for unusual

Lateral1 detections

Auto-extracted: 1 detections for lateral

Inject1 detections

Auto-extracted: 1 detections for inject

Masquerad1 detections

Auto-extracted: 1 detections for masquerad

Named Pipe1 detections

Auto-extracted: 1 detections for named pipe

Bypass1 detections

Auto-extracted: 1 detections for bypass

Network Connection Monitoring1 detections

Auto-extracted: 1 detections for network connection monitoring

Inject1 detections

Auto-extracted: 1 detections for inject

Parent Process1 detections

Auto-extracted: 1 detections for parent process

DETECTIONS (31)

*Detection Title*
kql
All BlackCat/ALPHV Ransomware IOCs with one KQL query
kql
Credential Manipulation - Detected - Elastic Endgame
elastichigh
Credential Manipulation - Prevented - Elastic Endgame
elasticmedium
First Time Seen NewCredentials Logon Process
elasticmedium
GKE API Request Impersonating Privileged Identity
elastichigh
HackTool - NoFilter Execution
sigmahigh
Interactive Logon by an Unusual Process
elastichigh
Kubernetes API Request Impersonating Privileged Identity
elastichigh
Parent Process PID Spoofing
elastichigh
Permission Theft - Detected - Elastic Endgame
elastichigh
Permission Theft - Prevented - Elastic Endgame
elasticmedium
Potential PowerShell HackTool Script by Function Names
elasticmedium
Potentially Suspicious Explicit Credential Local Logon
sigmamedium
PowerShell Script with Token Impersonation Capabilities
elasticmedium
Privilege Escalation via Named Pipe Impersonation
elastichigh
Privilege Escalation via Rogue Named Pipe Impersonation
elastichigh
Privileges Elevation via Parent Process PID Spoofing
elastichigh
Process Created with a Duplicated Token
elasticmedium
Process Created with an Elevated Token
elastichigh
Process Creation via Secondary Logon
elasticmedium
Process Primary Token Elevated to SeDebugPrivilege
kql
SeDebugPrivilege Enabled by a Suspicious Process
elasticmedium
Spike in Special Privilege Use Events
elasticlow
Suspicious Cross-User Process Spawn
sigmamedium
Suspicious SeIncreaseBasePriorityPrivilege Use
elastichigh
Suspicious SYSTEM User Process Creation
sigmahigh
Unusual Parent-Child Relationship
elasticmedium
Windows Privilege Escalation Suspicious Process Elevation
splunk_escu
Windows Privilege Escalation System Process Without System Parent
splunk_escu
Windows Privilege Escalation User Process Spawn System Process
splunk_escu