// MITRE ATT&CK
T1134 · Access Token Manipulation
🎯 Stealth Windows
Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls. Windows uses access tokens to determine the ownership of a running process. A user can manipulate access tokens to make a running process appear as though ...
How to detect & mitigate it
Detecting Access Token Manipulation starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (5)
T1134.001
Token Impersonation/Theft T1134.002
Create Process with Token T1134.003
Make and Impersonate Token T1134.004
Parent PID Spoofing T1134.005
SID-History Injection
Token Impersonation/Theft T1134.002
Create Process with Token T1134.003
Make and Impersonate Token T1134.004
Parent PID Spoofing T1134.005
SID-History Injection
Related techniques
T1055.011
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.