Umbra Wiki technique technique/T1134.003
Back to wiki

T1134.003 — Make and Impersonate Token

provenance: imported · ATT&CK: T1134.003

T1134.003: Make and Impersonate Token

MITRE ATT&CK® Enterprise technique

Tactics Stealth, Privilege Escalation
Platforms Windows
Permissions required
Version 2.0
Parent technique T1134

Description

Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls. For example, if an adversary has a username and password but the user is not logged onto the system the adversary can then create a logon session for the user using the LogonUser function.(Citation: LogonUserW function) The function will return a copy of the new session's access token and the adversary can use SetThreadToken to assign the token to a thread.

This behavior is distinct from Token Impersonation/Theft in that this refers to creating a new user token instead of stealing or duplicating an existing one.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1134/003
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/