Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0283 — Behavior-chain detection for T1134 Access Token Manipulation on Windows
DET0283

Behavior-chain detection for T1134 Access Token Manipulation on Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0786 Analytic 0786
Windows

Detection of suspicious token manipulation chains: use of token-related APIs (e.g., LogonUser, DuplicateTokenEx) or commands (runas) → spawning of a new process under a different security context (e.g., SYSTEM) → mismatched parent-child process lineage or anomalies in Event Tracing for Windows (ETW) token/PPID data → abnormal lateral or privilege escalation activity.

WinEventLog:Security EventCode=4672, 4634 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=10 ETW:Token token_analysis: API calls such as DuplicateTokenEx or ImpersonateLoggedOnUser WinEventLog:Security EventCode=5136
[TimeWindow] Correlation time between suspicious API usage, runas, and process creation (e.g., 5–10m).
[AllowedServiceAccounts] Whitelist of service accounts permitted to spawn SYSTEM-level processes.
[KnownAdminTools] Legitimate administrative utilities that trigger token changes.
[ParentProcessAnomalyThreshold] Deviation threshold for PPID mismatches detected via ETW.

Detected Techniques

1

Details

MITRE ID
DET0283
STIX ID
x-mitre-detection-strategy--774bbba8-45c2-403d-a445-3a64b3679faf
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.