Umbra Wiki technique technique/T1134.005
Back to wiki

T1134.005 — SID-History Injection

provenance: imported · ATT&CK: T1134.005

T1134.005: SID-History Injection

MITRE ATT&CK® Enterprise technique

Tactics Stealth, Privilege Escalation
Platforms Windows
Permissions required
Version 2.0
Parent technique T1134

Description

Adversaries may use SID-History Injection to escalate privileges and bypass access controls. The Windows security identifier (SID) is a unique value that identifies a user or group account. SIDs are used by Windows security in both security descriptors and access tokens. (Citation: Microsoft SID) An account can hold additional SIDs in the SID-History Active Directory attribute (Citation: Microsoft SID-History Attribute), allowing inter-operable account migration between domains (e.g., all values in SID-History are included in access tokens).

With Domain Administrator (or equivalent) rights, harvested or well-known SID values (Citation: Microsoft Well Known SIDs Jun 2017) may be inserted into SID-History to enable impersonation of arbitrary users/groups such as Enterprise Administrators. This manipulation may result in elevated access to local resources and/or access to otherwise inaccessible domains via lateral movement techniques such as Remote Services, SMB/Windows Admin Shares, or Windows Remote Management.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1134/005
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/