Access Token Manipulation T1134

Tactics: Stealth, Privilege Escalation

Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls. Windows uses access tokens to determine the ownership of a running process. A user can manipulate access tokens to make a running process appear as though it is the child of a different process or belongs to someone other than the user that started the process. When this occurs, the process also takes on the security context associated with the new token.

Events covered

24 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 10ProcessAccess
SysmonEvent ID 17PipeEvent (Pipe Created)
SysmonEvent ID 18PipeEvent (Pipe Connected)
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4648A logon was attempted using explicit credentials.
Security-AuditingEvent ID 4674An operation was attempted on a privileged object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4697A service was installed in the system.
Security-AuditingEvent ID 4703A user right was adjusted.
Security-AuditingEvent ID 4704A user right was assigned.
Security-AuditingEvent ID 4717System security access was granted to an account.
Security-AuditingEvent ID 4738A user account was changed.
Security-AuditingEvent ID 4742A computer account was changed.
Security-AuditingEvent ID 4765SID History was added to an account.
Security-AuditingEvent ID 4766An attempt to add SID History to an account failed.
Security-AuditingEvent ID 5136A directory service object was modified.
Security-AuditingEvent ID 5447A Windows Filtering Platform filter has been changed.
Security-AuditingEvent ID 5449A Windows Filtering Platform provider context has been changed.
1Password-ServiceAccountTokenanyService account token (catch-all)
Defender-DeviceLogonEventsanyLogon activity
Defender-DeviceProcessEventsanyProcess activity
Defender-DeviceProcessEventsProcessCreatedProcess created
Service-Control-ManagerEvent ID 7045A service was installed in the system.

Authoring guide

These 98 rules share fields, values, and exclusions.

Fields filtered most (127 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType29eq 29start, log_on, end, token_manipulation_event, token_protection_event
Image22ends_with 9, is_not_null 4, starts_with 4, in 2, wildcard 2, contains 1, eq 1c:\, *\\\\*, *\\programdata\\*, *\\temp\\*, \cmd.exe
CommandLine16contains 13, ends_with 3, match 1, regex_match 1, wildcard 1/user:, -decode , -e* aqblahga, -e* awv4i, -spawnto
EventID15eq 14, in 110, 4738, 4742, 5136, 1
user.id15eq 8, starts_with 6, ne 3, is_not_null 1S-1-5-18, S-1-12-, S-1-5-21, s-1-5-18, S-1-12-1-
ParentImage13is_not_null 6, ends_with 3, in 2, contains 1, regex_match 1, starts_with 1*\\\\*, *\\programdata\\*, *\\temp\\*, (c:\\windows\\system32\\[a-z0-9\-\_\.]+\.exe|c:\\windows\..., :\packages\plugins\microsoft.guestconfiguration.configura...
process.parent.Ext.real.pid11gt 10, is_null 10
process_name11eq 6, in 3, ends_with 1, starts_with 1cmd.exe, certutil.exe, msbuild.exe, powershell.exe, \svchost.exe
OriginalFileName9eq 6, in 2, contains 1cmd.exe, powershell.exe, advancedrun.exe, browsercore.exe, cmstp.exe
host.os.type9eq 9
event.category7eq 7iam, authentication, process
Channel5eq 5, in 5
Hashes5contains 2, ne 2, is_not_null 18ba8760bcb924e1e7943c3008a80006b29737808cc41a93cabcfeaaec9785276, 9e23e07e042943e1862b86d8c9dc05483a118938f5b19f359cb8f9aa6a14a452, imphash=04d974875bd225f00902b4cad9af3fbc, imphash=0a358ffc1697b7a07d0e817ac740df62, imphash=89059503d7fbf470e68f7e63313da3ad
IntegrityLevel5eq 5, in 2System, High, Low, Medium
LogonProcessName5starts_with 3, eq 2Advapi, seclogo, advapi

Top indicator values (996 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
start
19391
EventTypeeq
log_on
48
EventTypeeq
end
218
EventTypeeq
token_manipulation_event
22
EventTypeeq
token_protection_event
22
EventTypeeq
token_right_adjusted
22
process.parent.Ext.real.pidgt
0
1011
IntegrityLeveleq
System
530
event.kindeq
alert
438
event.moduleeq
endgame
415
event.typeeq
start
41078
user.ideq
S-1-5-18
46
user.ideq
s-1-5-18
413
user.idstarts_with
S-1-12-
446
user.idstarts_with
S-1-5-21
447
EventIDeq
10
323
EventIDeq
5136
345
EventIDeq
4738
28
EventIDeq
4742
26
Imagestarts_with
c:\
316
Signaturestarts_with
Microsoft
322
event.categoryeq
iam
38
event.outcomeeq
success
3369
src_ipeq
::1
37
usercontains
authori
314
usercontains
autori
314
user.effective.idstarts_with
S-1-12-
34
user.effective.idstarts_with
S-1-5-21
34
CommandLinecontains
/user:
27
EnabledPrivilegeListeq
SeDebugPrivilege
22

Exclusions (922 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.code_signature.trustedeq
true
17
process_nameeq
rundll32.exe
9
process_nameeq
powershell.exe
8
Imageeq
?:\windows\system32\werfault.exe
8
Imageeq
?:\windows\syswow64\werfault.exe
7
Imageeq
?:\windows\system32\werfaultsecure.exe
6
Imageeq
?:\windows\system32\wermgr.exe
6
Imageeq
?:\windows\softwaredistribution\download\install\securityhealthsetup.exe
4
Imageeq
?:\windows\syswow64\werfaultsecure.exe
4
Imageeq
?:\windows\system32\mpsigstub.exe
3
Imageeq
?:\windows\system32\svchost.exe
3
ParentImageeq
?:\windows\system32\svchost.exe
6
ParentImageeq
?:\windows\system32\utilman.exe
4
Imagewildcard
?:\program files (x86)\*.exe
5
Imagewildcard
?:\program files\*.exe
5

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 22 rules

Elastic 41 rules

Splunk 14 rules

Kusto 16 rules

Panther 5 rules