This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential Access Token Abuse
Original Source:
[Sigma source]
Title:
Potential Access Token Abuse
Status:
test
Description:
Detects potential token impersonation and theft. Example, when using "DuplicateToken(Ex)" and "ImpersonateLoggedOnUser" with the "LOGON32_LOGON_NEW_CREDENTIALS flag".
References:
-https://www.elastic.co/fr/blog/how-attackers-abuse-access-token-manipulation
-https://www.manageengine.com/log-management/cyber-security/access-token-manipulation.html
Author:
Michaela Adams, Zach Mathis
Date:
2022-11-06
modified:
2023-04-26
Tags:
-'attack.privilege-escalation'
-'attack.stealth'
-'attack.t1134.001'
-'stp.4u'
Logsource:
product: windows
service: security
Detection:
selection:
EventID
:
'4624'
LogonType
:
'9'
LogonProcessName
:
'Advapi'
AuthenticationPackageName
:
'Negotiate'
ImpersonationLevel
:
'%%1833'
condition
:
selection
Falsepositives:
-Anti-Virus
Level:
medium