Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0482 — Behavior-chain detection for T1134.001 Access Token Manipulation: Token Impersonation/Theft on Windows
DET0482

Behavior-chain detection for T1134.001 Access Token Manipulation: Token Impersonation/Theft on Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1324 Analytic 1324
Windows

Detection of token duplication and impersonation attempts by correlating suspicious command-line executions (e.g., runas) with API calls to DuplicateToken, DuplicateTokenEx, ImpersonateLoggedOnUser, or SetThreadToken. The chain includes the initial command execution or in-memory API invocation → token handle duplication or thread token assignment → a new or existing process assuming the impersonated user's context.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=10 ETW:Token api_call: DuplicateTokenEx, ImpersonateLoggedOnUser, SetThreadToken
[AllowedSystemProcesses] Whitelist of known processes that legitimately duplicate tokens (e.g., services.exe).
[TimeWindow] Time interval between API call and subsequent impersonated process (e.g., 5m).
[UserContextFilter] Filter for service accounts or known administrative accounts that perform legitimate impersonation.
[ParentProcessAnomalyThreshold] Threshold for parent-child process lineage anomalies indicating token theft.

Detected Techniques

1

Details

MITRE ID
DET0482
STIX ID
x-mitre-detection-strategy--0b06e42c-ab1c-4fb7-834b-10293e904173
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.