Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1134.002 Create Process with Token |
MalwareBankshot | Bankshot grabs a user token using WTSQueryUserToken and then creates a process by impersonating a logged-on user. |
| T1134.002 Create Process with Token |
MalwareTONESHELL | TONESHELL included functionality to create sub-processes with a specific user’s token. |
| T1134.002 Create Process with Token |
MalwareAria-body | Aria-body has the ability to execute a process using |
| T1134.002 Create Process with Token |
MalwareWhisperGate | The WhisperGate third stage can use the AdvancedRun.exe tool to execute commands in the context of the Windows TrustedInstaller group via `%TEMP%\AdvancedRun.exe" /EXEFilename "C:\Windows\System32\sc.exe" /WindowState 0 /CommandLine "stop WinDefend" /StartDirectory "" /RunAs 8 /Run`. |
| T1134.002 Create Process with Token |
MalwarePipeMon | PipeMon can attempt to gain administrative privileges using token impersonation. |
| T1134.002 Create Process with Token |
MalwareKONNI | KONNI has duplicated the token of a high integrity process to spawn an instance of cmd.exe under an impersonated user. |
| T1134.002 Create Process with Token |
MalwareREvil | REvil can launch an instance of itself with administrative rights using runas. |
| T1134.002 Create Process with Token |
MalwareZxShell | ZxShell has a command called RunAs, which creates a new process as another user or process context. |
| T1134.002 Create Process with Token |
MalwareAzorult | Azorult can call WTSQueryUserToken and CreateProcessAsUser to start a new process with local system privileges. |
| T1134.002 Create Process with Token |
ToolEmpire | Empire can use |
| T1134.002 Create Process with Token |
ToolPoshC2 | PoshC2 can use Invoke-RunAs to make tokens. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.