T1134.003 — Make and Impersonate Token
T1134.003: Make and Impersonate Token
MITRE ATT&CK® Enterprise technique
| Tactics | Stealth, Privilege Escalation |
| Platforms | Windows |
| Permissions required | — |
| Version | 2.0 |
| Parent technique | T1134 |
Description
Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls. For example, if an adversary has a username and password but the user is not logged onto the system the adversary can then create a logon session for the user using the LogonUser function.(Citation: LogonUserW function) The function will return a copy of the new session's access token and the adversary can use SetThreadToken to assign the token to a thread.
This behavior is distinct from Token Impersonation/Theft in that this refers to creating a new user token instead of stealing or duplicating an existing one.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1134/003
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/