Sub-technique of T1134 Access Token Manipulation.View on attack.mitre.org
Adversaries may use SID-History Injection to escalate privileges and bypass access controls. The Windows security identifier (SID) is a unique value that identifies a user or group account. SIDs are used by Windows security in both security descriptors and access tokens. An account can hold additional SIDs in the SID-History Active Directory attribute , allowing inter-operable account migration between domains (e.g., all values in SID-History are included in access tokens).
With Domain Administrator (or equivalent) rights, harvested or well-known SID values may be inserted into SID-History to enable impersonation of arbitrary users/groups such as Enterprise Administrators. This manipulation may result in elevated access to local resources and/or access to otherwise inaccessible domains via lateral movement techniques such as Remote Services, SMB/Windows Admin Shares, or Windows Remote Management.
Rules on DetectionCode tagged with T1134.005.
| Rule | Level | Log source |
|---|---|---|
| Addition of SID History to Active Directory Object | medium | windows / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows AD Cross Domain SID History Addition | TTP | NULL | Windows Event Log Security 4742, Windows Event Log Security 4738 |
| Windows AD Privileged Account SID History Addition | TTP | NULL | Windows Event Log Security 4742, Windows Event Log Security 4738 |
| Windows AD Same Domain SID History Addition | TTP | NULL | Windows Event Log Security 4742, Windows Event Log Security 4738 |
| Windows AD SID History Attribute Modified | TTP | NULL | Windows Event Log Security 5136 |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| ToolEmpire | Empire can add a SID-History to a user if on a domain controller. |
| ToolMimikatz | Mimikatz's |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.