Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0498 — Behavior‑chain detection for T1134.003 Make and Impersonate Token (Windows)
DET0498

Behavior‑chain detection for T1134.003 Make and Impersonate Token (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1375 Analytic 1375
Windows

A process creates a brand‑new logon session/token (LogonUser*/LsaLogonUser) and then assigns/impersonates it (SetThreadToken/ImpersonateLoggedOnUser) to run actions under that freshly created security context. Chain: (1) suspicious command or script block (e.g., runas /netonly, PowerShell P/Invoke of LogonUser) → (2) ETW/API evidence of LogonUser*/SetThreadToken → (3) Security 4624 New Logon (often LogonType=9 NewCredentials or 2/3 from a non‑interactive parent) with no interactive desktop → (4) sysmon 1 process(es) executing with the new LogonId/SID different from the parent process → (5) optional privileged ops/lateral movement.

WinEventLog:Security EventCode=4688 WinEventLog:Security EventCode=4672 etw:Microsoft-Windows-Security-Auditing api_call: LogonUser(A|W), LsaLogonUser, SetThreadToken, ImpersonateLoggedOnUser
[TimeWindow] Correlation window between LogonUser*/SetThreadToken and the first spawned process (default 5–10 minutes).
[SuspiciousLogonTypes] Which 4624 LogonTypes to treat as high risk (e.g., 9 NewCredentials, 3 Network when sourced locally).
[AllowedImpersonators] Processes/accounts legitimately creating tokens (e.g., winlogon.exe, lsass.exe, IIS worker, trusted service accounts).
[ParentChildUserMismatch] Whether to alert on any SID/LogonId mismatch between parent/child not in allow-list.
[IntegrityEscalationDelta] Minimum integrity level jump (e.g., Medium→High/System) to raise severity.

Detected Techniques

1

Details

MITRE ID
DET0498
STIX ID
x-mitre-detection-strategy--d9cf8032-7b53-4251-8519-a7ccbf6a027a
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.