Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1134 Access Token Manipulation |
MalwareAppleSeed | AppleSeed can gain system level privilege by passing |
| T1134 Access Token Manipulation |
MalwareSslMM | SslMM contains a feature to manipulate process privileges and tokens. |
| T1134 Access Token Manipulation |
MalwareMafalda | Mafalda can use `AdjustTokenPrivileges()` to elevate privileges. |
| T1134 Access Token Manipulation |
MalwareBlackCat | BlackCat has the ability modify access tokens. |
| T1134 Access Token Manipulation |
MalwareCuba | Cuba has used |
| T1134 Access Token Manipulation |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can adjust token privileges. |
| T1134 Access Token Manipulation |
MalwareSagerunex | Sagerunex finds the `explorer.exe` process after execution and uses it to change the token of its executing thread. |
| T1134 Access Token Manipulation |
MalwareMegaCortex | MegaCortex can enable |
| T1134 Access Token Manipulation |
MalwareRyuk | Ryuk has attempted to adjust its token privileges to have the |
| T1134 Access Token Manipulation |
MalwareHermeticWiper | HermeticWiper can use `AdjustTokenPrivileges` to grant itself privileges for debugging with `SeDebugPrivilege`, creating backups with `SeBackupPrivilege`, loading drivers with `SeLoadDriverPrivilege`, and shutting down a local system with `SeShutdownPrivilege`. |
| T1134 Access Token Manipulation |
MalwareSUNSPOT | SUNSPOT modified its security token to grants itself debugging privileges by adding |
| T1134 Access Token Manipulation |
MalwareKillDisk | KillDisk has attempted to get the access token of a process by calling |
| T1134 Access Token Manipulation |
MalwareQilin | Qilin can use an embedded Mimikatz module for token manipulation. |
| T1134 Access Token Manipulation |
MalwareGelsemium | Gelsemium can use token manipulation to bypass UAC on Windows7 systems. |
| T1134 Access Token Manipulation |
ToolSliver | Sliver has the ability to manipulate user tokens on targeted Windows systems. |
| T1134 Access Token Manipulation |
ToolPowerSploit | PowerSploit's |
| T1134 Access Token Manipulation |
ToolEmpire | Empire can use PowerSploit's |
| T1134 Access Token Manipulation |
ToolPoshC2 | PoshC2 can use Invoke-TokenManipulation for manipulating tokens. |
| T1134 Access Token Manipulation |
MalwareDuqu | Duqu examines running system processes for tokens that have specific system privileges. If it finds one, it will copy the token and store it for later use. Eventually it will start new processes with the stored token attached. It can also steal tokens to acquire administrative privileges. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.