ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1134×

19 examples

TechniqueUsed byProcedure example
T1134
Access Token Manipulation
MalwareAppleSeed

AppleSeed can gain system level privilege by passing SeDebugPrivilege to the AdjustTokenPrivilege API.

T1134
Access Token Manipulation
MalwareSslMM

SslMM contains a feature to manipulate process privileges and tokens.

T1134
Access Token Manipulation
MalwareMafalda

Mafalda can use `AdjustTokenPrivileges()` to elevate privileges.

T1134
Access Token Manipulation
MalwareBlackCat

BlackCat has the ability modify access tokens.

T1134
Access Token Manipulation
MalwareCuba

Cuba has used SeDebugPrivilege and AdjustTokenPrivileges to elevate privileges.

T1134
Access Token Manipulation
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can adjust token privileges.

T1134
Access Token Manipulation
MalwareSagerunex

Sagerunex finds the `explorer.exe` process after execution and uses it to change the token of its executing thread.

T1134
Access Token Manipulation
MalwareMegaCortex

MegaCortex can enable SeDebugPrivilege and adjust token privileges.

T1134
Access Token Manipulation
MalwareRyuk

Ryuk has attempted to adjust its token privileges to have the SeDebugPrivilege.

T1134
Access Token Manipulation
MalwareHermeticWiper

HermeticWiper can use `AdjustTokenPrivileges` to grant itself privileges for debugging with `SeDebugPrivilege`, creating backups with `SeBackupPrivilege`, loading drivers with `SeLoadDriverPrivilege`, and shutting down a local system with `SeShutdownPrivilege`.

T1134
Access Token Manipulation
MalwareSUNSPOT

SUNSPOT modified its security token to grants itself debugging privileges by adding SeDebugPrivilege.

T1134
Access Token Manipulation
MalwareKillDisk

KillDisk has attempted to get the access token of a process by calling OpenProcessToken. If KillDisk gets the access token, then it attempt to modify the token privileges with AdjustTokenPrivileges.

T1134
Access Token Manipulation
MalwareQilin

Qilin can use an embedded Mimikatz module for token manipulation.

T1134
Access Token Manipulation
MalwareGelsemium

Gelsemium can use token manipulation to bypass UAC on Windows7 systems.

T1134
Access Token Manipulation
ToolSliver

Sliver has the ability to manipulate user tokens on targeted Windows systems.

T1134
Access Token Manipulation
ToolPowerSploit

PowerSploit's Invoke-TokenManipulation Exfiltration module can be used to manipulate tokens.

T1134
Access Token Manipulation
ToolEmpire

Empire can use PowerSploit's Invoke-TokenManipulation to manipulate access tokens.

T1134
Access Token Manipulation
ToolPoshC2

PoshC2 can use Invoke-TokenManipulation for manipulating tokens.

T1134
Access Token Manipulation
MalwareDuqu

Duqu examines running system processes for tokens that have specific system privileges. If it finds one, it will copy the token and store it for later use. Eventually it will start new processes with the stored token attached. It can also steal tokens to acquire administrative privileges.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.