SID-History Injection

T1134.005

Sub-technique of T1134 Access Token Manipulation.View on attack.mitre.org

About this technique

Adversaries may use SID-History Injection to escalate privileges and bypass access controls. The Windows security identifier (SID) is a unique value that identifies a user or group account. SIDs are used by Windows security in both security descriptors and access tokens. An account can hold additional SIDs in the SID-History Active Directory attribute , allowing inter-operable account migration between domains (e.g., all values in SID-History are included in access tokens).

With Domain Administrator (or equivalent) rights, harvested or well-known SID values may be inserted into SID-History to enable impersonation of arbitrary users/groups such as Enterprise Administrators. This manipulation may result in elevated access to local resources and/or access to otherwise inaccessible domains via lateral movement techniques such as Remote Services, SMB/Windows Admin Shares, or Windows Remote Management.

Detection rules5

Rules on DetectionCode tagged with T1134.005.

Sigma1

RuleLevelLog source
Addition of SID History to Active Directory Objectmediumwindows / NULL

Splunk4

RuleTypeRiskData source
Windows AD Cross Domain SID History AdditionTTPNULLWindows Event Log Security 4742, Windows Event Log Security 4738
Windows AD Privileged Account SID History AdditionTTPNULLWindows Event Log Security 4742, Windows Event Log Security 4738
Windows AD Same Domain SID History AdditionTTPNULLWindows Event Log Security 4742, Windows Event Log Security 4738
Windows AD SID History Attribute ModifiedTTPNULLWindows Event Log Security 5136

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples2

Software2

Used byProcedure example
ToolEmpire

Empire can add a SID-History to a user if on a domain controller.

ToolMimikatz

Mimikatz's MISC::AddSid module can append any SID or user/group account to a user's SID-History. Mimikatz also utilizes SID-History Injection to expand the scope of other components such as generated Kerberos Golden Tickets and DCSync beyond a single domain.

References3

  1. Microsoft SID Open source
    Microsoft. (n.d.). Security Identifiers. Retrieved November 30, 2017.
  2. Microsoft SID-History Attribute Open source
    Microsoft. (n.d.). Active Directory Schema - SID-History attribute. Retrieved November 30, 2017.
  3. Microsoft Well Known SIDs Jun 2017 Open source
    Microsoft. (2017, June 23). Well-known security identifiers in Windows operating systems. Retrieved November 30, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.