Potential Access Token Abuse

 Original Source: [Sigma source]
Title: Potential Access Token Abuse
Status: test
Description:Detects potential token impersonation and theft. Example, when using "DuplicateToken(Ex)" and "ImpersonateLoggedOnUser" with the "LOGON32_LOGON_NEW_CREDENTIALS flag".
References:
  -https://www.elastic.co/fr/blog/how-attackers-abuse-access-token-manipulation
  -https://www.manageengine.com/log-management/cyber-security/access-token-manipulation.html
Author: Michaela Adams, Zach Mathis
Date: 2022-11-06
modified:2023-04-26
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1134.001'
  • -'stp.4u'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '4624'
    LogonType: '9'
    LogonProcessName: 'Advapi'
    AuthenticationPackageName: 'Negotiate'
    ImpersonationLevel: '%%1833'
  condition:selection
Falsepositives:
  -Anti-Virus
Level: medium