Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1134 Access Token Manipulation |
MalwareMafalda | Mafalda can use `AdjustTokenPrivileges()` to elevate privileges. |
| T1134 Access Token Manipulation |
MalwareBlackCat | BlackCat has the ability modify access tokens. |
| T1134 Access Token Manipulation |
MalwareCuba | Cuba has used |
| T1134 Access Token Manipulation |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can adjust token privileges. |
| T1134 Access Token Manipulation |
MalwareSagerunex | Sagerunex finds the `explorer.exe` process after execution and uses it to change the token of its executing thread. |
| T1134 Access Token Manipulation |
MalwareMegaCortex | MegaCortex can enable |
| T1134 Access Token Manipulation |
MalwareRyuk | Ryuk has attempted to adjust its token privileges to have the |
| T1134 Access Token Manipulation |
MalwareHermeticWiper | HermeticWiper can use `AdjustTokenPrivileges` to grant itself privileges for debugging with `SeDebugPrivilege`, creating backups with `SeBackupPrivilege`, loading drivers with `SeLoadDriverPrivilege`, and shutting down a local system with `SeShutdownPrivilege`. |
| T1134 Access Token Manipulation |
MalwareSUNSPOT | SUNSPOT modified its security token to grants itself debugging privileges by adding |
| T1134 Access Token Manipulation |
MalwareKillDisk | KillDisk has attempted to get the access token of a process by calling |
| T1134 Access Token Manipulation |
MalwareQilin | Qilin can use an embedded Mimikatz module for token manipulation. |
| T1134 Access Token Manipulation |
MalwareGelsemium | Gelsemium can use token manipulation to bypass UAC on Windows7 systems. |
| T1134 Access Token Manipulation |
ToolSliver | Sliver has the ability to manipulate user tokens on targeted Windows systems. |
| T1134 Access Token Manipulation |
ToolPowerSploit | PowerSploit's |
| T1134 Access Token Manipulation |
ToolEmpire | Empire can use PowerSploit's |
| T1134 Access Token Manipulation |
ToolPoshC2 | PoshC2 can use Invoke-TokenManipulation for manipulating tokens. |
| T1134 Access Token Manipulation |
MalwareDuqu | Duqu examines running system processes for tokens that have specific system privileges. If it finds one, it will copy the token and store it for later use. Eventually it will start new processes with the stored token attached. It can also steal tokens to acquire administrative privileges. |
| T1134.001 Token Impersonation/Theft |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used custom tooling to acquire tokens using `ImpersonateLoggedOnUser/SetThreadToken`. |
| T1134.001 Token Impersonation/Theft |
GroupAPT28 | APT28 has used CVE-2015-1701 to access the SYSTEM token and copy it into the current process as part of privilege escalation. |
| T1134.001 Token Impersonation/Theft |
GroupFIN8 | FIN8 has used a malicious framework designed to impersonate the lsass.exe/vmtoolsd.exe token. |
| T1134.001 Token Impersonation/Theft |
MalwareStuxnet | Stuxnet attempts to impersonate an anonymous token to enumerate bindings in the service control manager. |
| T1134.001 Token Impersonation/Theft |
MalwareHavoc | Havoc has a module capable of token impersonation. |
| T1134.001 Token Impersonation/Theft |
MalwareAria-body | Aria-body has the ability to duplicate a token from ntprint.exe. |
| T1134.001 Token Impersonation/Theft |
MalwareEmotet | Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed. |
| T1134.001 Token Impersonation/Theft |
MalwareBADHATCH | BADHATCH can impersonate a `lsass.exe` or `vmtoolsd.exe` token. |
| T1134.001 Token Impersonation/Theft |
MalwareOkrum | Okrum can impersonate a logged-on user's security context using a call to the ImpersonateLoggedOnUser API. |
| T1134.001 Token Impersonation/Theft |
MalwareSiloscape | Siloscape impersonates the main thread of |
| T1134.001 Token Impersonation/Theft |
MalwareFooder | Fooder has used the `DuplicateTokenEx` API to duplicate the token of a specified process, and `CreateProcessAsUserA` to execute its payload. |
| T1134.001 Token Impersonation/Theft |
MalwareLP-Notes | LP-Notes has impersonated the security context of the taskhostw.exe process via the `ImpersonateLoggedOnUser` API. |
| T1134.001 Token Impersonation/Theft |
MalwareShamoon | Shamoon can impersonate tokens using |
| T1134.001 Token Impersonation/Theft |
MalwareTarrask | Tarrask leverages token theft to obtain `lsass.exe` security permissions. |
| T1134.001 Token Impersonation/Theft |
MalwareFinFisher | FinFisher uses token manipulation with NtFilterToken as part of UAC bypass. |
| T1134.001 Token Impersonation/Theft |
MalwareCobalt Strike | Cobalt Strike can steal access tokens from exiting processes. |
| T1134.001 Token Impersonation/Theft |
MalwareREvil | REvil can obtain the token from the user that launched the explorer.exe process to avoid affecting the desktop of the SYSTEM user. |
| T1134.001 Token Impersonation/Theft |
MalwareBitPaymer | BitPaymer can use the tokens of users to create processes on infected systems. |
| T1134.001 Token Impersonation/Theft |
ToolSILENTTRINITY | SILENTTRINITY can find a process owned by a specific user and impersonate the associated token. |
| T1134.001 Token Impersonation/Theft |
ToolPupy | Pupy can obtain a list of SIDs and provide the option for selecting process tokens to impersonate. |
| T1134.002 Create Process with Token |
GroupTurla | Turla RPC backdoors can impersonate or steal process tokens before executing commands. |
| T1134.002 Create Process with Token |
GroupLazarus Group | Lazarus Group keylogger KiloAlfa obtains user tokens from interactive sessions to execute itself with API call |
| T1134.002 Create Process with Token |
MalwareBankshot | Bankshot grabs a user token using WTSQueryUserToken and then creates a process by impersonating a logged-on user. |
| T1134.002 Create Process with Token |
MalwareTONESHELL | TONESHELL included functionality to create sub-processes with a specific user’s token. |
| T1134.002 Create Process with Token |
MalwareAria-body | Aria-body has the ability to execute a process using |
| T1134.002 Create Process with Token |
MalwareWhisperGate | The WhisperGate third stage can use the AdvancedRun.exe tool to execute commands in the context of the Windows TrustedInstaller group via `%TEMP%\AdvancedRun.exe" /EXEFilename "C:\Windows\System32\sc.exe" /WindowState 0 /CommandLine "stop WinDefend" /StartDirectory "" /RunAs 8 /Run`. |
| T1134.002 Create Process with Token |
MalwarePipeMon | PipeMon can attempt to gain administrative privileges using token impersonation. |
| T1134.002 Create Process with Token |
MalwareKONNI | KONNI has duplicated the token of a high integrity process to spawn an instance of cmd.exe under an impersonated user. |
| T1134.002 Create Process with Token |
MalwareREvil | REvil can launch an instance of itself with administrative rights using runas. |
| T1134.002 Create Process with Token |
MalwareZxShell | ZxShell has a command called RunAs, which creates a new process as another user or process context. |
| T1134.002 Create Process with Token |
MalwareAzorult | Azorult can call WTSQueryUserToken and CreateProcessAsUser to start a new process with local system privileges. |
| T1134.002 Create Process with Token |
ToolEmpire | Empire can use |
| T1134.002 Create Process with Token |
ToolPoshC2 | PoshC2 can use Invoke-RunAs to make tokens. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.