Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0456 — Behavior-chain detection for T1134.002 Create Process with Token (Windows)
DET0456

Behavior-chain detection for T1134.002 Create Process with Token (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1253 Analytic 1253
Windows

A process (often after stealing/creating a token) calls CreateProcessWithTokenW/CreateProcessAsUserW or uses runas to spawn a **new** process whose security context (SID/LogonId/IntegrityLevel) differs from its parent. Chain: (1) suspicious command/API → (2) privileged handle or token duplication/open → (3) new child process running as another user / higher integrity → (4) optional follow‑on privileged/lateral actions.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=10 ETW:ProcThread api_call: CreateProcessWithTokenW, CreateProcessAsUserW WinEventLog:Security EventCode=4672, 4634 WinEventLog:Security EventCode=5136
[TimeWindow] Correlation window between API/handle access and the spawned process (default 5–10 minutes).
[AllowedImpersonators] Service accounts/binaries legitimately using CreateProcessWithTokenW (e.g., PsExec service, SCCM, backup agents).
[IntegrityEscalationDelta] Minimum jump in integrity level (e.g., Medium→System) to flag.
[ParentChildUserMismatch] Treat any parent/child SID or LogonId mismatch as suspicious unless on allow-list.
[SensitiveTargets] List of processes (e.g., lsass.exe, winlogon.exe, services.exe) whose token access prior to the spawn raises score.

Detected Techniques

1

Details

MITRE ID
DET0456
STIX ID
x-mitre-detection-strategy--78aa8d17-c96f-4ba9-b431-f91157f38553
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.