T1134.003 Make and Impersonate Token
Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls. For example, if an adversary has a username and password but the user is not logged onto the system the adversary can then create a logon session for the user using the LogonUser function.2 The function will return a copy of the new session’s access token and the adversary can use SetThreadToken to assign the token to a thread.
This behavior is distinct from Token Impersonation/Theft in that this refers to creating a new user token instead of stealing or duplicating an existing one.
| Item | Value |
|---|---|
| ID | T1134.003 |
| Sub-techniques | T1134.001, T1134.002, T1134.003, T1134.004, T1134.005 |
| Tactics | TA0005, TA0004 |
| Platforms | Windows |
| Version | 1.2 |
| Created | 18 February 2020 |
| Last Modified | 24 October 2025 |
Procedure Examples
| ID | Name | Description |
|---|---|---|
| G1043 | BlackByte | BlackByte constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution.9 |
| S0154 | Cobalt Strike | Cobalt Strike can make tokens from known credentials.8 |
| G1016 | FIN13 | FIN13 has utilized tools such as Incognito V2 for token manipulation and impersonation.10 |
| S1060 | Mafalda | Mafalda can create a token for a different user.7 |
| S0692 | SILENTTRINITY | SILENTTRINITY can make tokens from known credentials.6 |
Mitigations
| ID | Mitigation | Description |
|---|---|---|
| M1026 | Privileged Account Management | Limit permissions so that users and user groups cannot create tokens. This setting should be defined for the local system account only. GPO: Computer Configuration > [Policies] > Windows Settings > Security Settings > Local Policies > User Rights Assignment: Create a token object. 3 Also define who can create a process level token to only the local and network service through GPO: Computer Configuration > [Policies] > Windows Settings > Security Settings > Local Policies > User Rights Assignment: Replace a process level token.4 |
| M1018 | User Account Management | An adversary must already have administrator level access on the local system to make full use of this technique; be sure to restrict users and accounts to the least privileges they require. |
References
-
Mathers, B. (2017, March 7). Command line process auditing. Retrieved April 21, 2017. ↩
-
Microsoft. (2023, March 10). LogonUserW function (winbase.h). Retrieved January 8, 2024. ↩
-
Brower, N., Lich, B. (2017, April 19). Create a token object. Retrieved December 19, 2017. ↩
-
Brower, N., Lich, B. (2017, April 19). Replace a process level token. Retrieved December 19, 2017. ↩
-
Microsoft TechNet. (n.d.). Runas. Retrieved April 21, 2017. ↩
-
byt3bl33d3r. (n.d.). SILENTTRINITY. Retrieved September 12, 2024. ↩
-
SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023. ↩
-
Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017. ↩
-
Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024. ↩
-
Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023. ↩