T1134 Access Token Manipulation
Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls. Windows uses access tokens to determine the ownership of a running process. A user can manipulate access tokens to make a running process appear as though it is the child of a different process or belongs to someone other than the user that started the…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- HackTool - Koh Default Named Pipecriticaltest · windows
- HackTool - NoFilter Executionhightest · windows
- HackTool - PPID Spoofing SelectMyParent Tool Executionhightest · windows
- HackTool - SharpDPAPI Executionhightest · windows
- HackTool - SharpImpersonation Executionhightest · windows
- Meterpreter or Cobalt Strike Getsystem Service Installation - Securityhightest · windows
- Meterpreter or Cobalt Strike Getsystem Service Installation - Systemhightest · windows
- PUA - AdvancedRun Suspicious Executionhightest · windows
- Potential Meterpreter/CobaltStrike Activityhightest · windows
- Suspicious Child Process Created as Systemhightest · windows
- Suspicious SYSTEM User Process Creationhightest · windows
- RedSun - Conhost.exe Spawned by TieringEngineService.exehighexperimental · windows
- Addition of SID History to Active Directory Objectmediumstable · windows
- HackTool - Impersonate Executionmediumtest · windows
- PUA - AdvancedRun Executionmediumtest · windows
- Potential Access Token Abusemediumtest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.