Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0136 — Behavior-chain detection for T1134.005 Access Token Manipulation: SID-History Injection (Windows)
DET0136

Behavior-chain detection for T1134.005 Access Token Manipulation: SID-History Injection (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0383 Analytic 0383
Windows

Detection of unauthorized modification of Active Directory SID-History attributes to escalate privileges. This chain involves: (1) privileged operations or API calls to DsAddSidHistory or related AD modification functions, (2) observed attribute changes in SID-History (Event ID 5136), (3) new logon sessions where the token includes unexpected or privileged SID-History values, and (4) follow-on resource access using elevated privileges derived from SID-History injection.

WinEventLog:Security EventCode=5136 WinEventLog:Security EventCode=4720, 4738 etw:Microsoft-Windows-Directory-Services-SAM api_call: Calls to DsAddSidHistory or related RPC operations
[AllowedSIDHistoryChanges] Approved migration windows or known SID-History population events.
[TimeWindow] Correlation window between attribute change and suspicious logon activity (default 15–30 minutes).
[PrivilegedSIDList] List of sensitive SIDs (e.g., Enterprise Admins, Domain Admins) that should never appear in SID-History.
[UserContextFilter] Exclude trusted migration service accounts or pre-approved administrative tasks.
[AnomalousSIDCountThreshold] Raise alerts when a token contains more than X SID-History entries (default X=2).

Detected Techniques

1

Details

MITRE ID
DET0136
STIX ID
x-mitre-detection-strategy--d32792e2-f927-492b-91bf-ac478cf64868
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.