{"id":"T1134.005","name":"SID-History Injection","url":"https://attack.mitre.org/techniques/T1134/005","tactics":["stealth","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0136","stix_id":"x-mitre-detection-strategy--d32792e2-f927-492b-91bf-ac478cf64868","name":"Behavior-chain detection for T1134.005 Access Token Manipulation: SID-History Injection (Windows)","url":"https://attack.mitre.org/detectionstrategies/DET0136","analytics":[{"id":"AN0383","stix_id":"x-mitre-analytic--c061d938-cafa-4e9d-8729-29d63ba633ad","name":"Analytic 0383","description":"Detection of unauthorized modification of Active Directory SID-History attributes to escalate privileges. This chain involves: (1) privileged operations or API calls to DsAddSidHistory or related AD modification functions, (2) observed attribute changes in SID-History (Event ID 5136), (3) new logon sessions where the token includes unexpected or privileged SID-History values, and (4) follow-on resource access using elevated privileges derived from SID-History injection.","url":"https://attack.mitre.org/detectionstrategies/DET0136#AN0383","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=5136","data_component":"DC0066","data_component_name":"Active Directory Object Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4720, 4738","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"wineventlog-security"},{"name":"etw:Microsoft-Windows-Directory-Services-SAM","channel":"api_call: Calls to DsAddSidHistory or related RPC operations","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"etw-microsoft-windows-directory-services-sam"}],"mutable_elements":[{"field":"AllowedSIDHistoryChanges","description":"Approved migration windows or known SID-History population events."},{"field":"TimeWindow","description":"Correlation window between attribute change and suspicious logon activity (default 15–30 minutes)."},{"field":"PrivilegedSIDList","description":"List of sensitive SIDs (e.g., Enterprise Admins, Domain Admins) that should never appear in SID-History."},{"field":"UserContextFilter","description":"Exclude trusted migration service accounts or pre-approved administrative tasks."},{"field":"AnomalousSIDCountThreshold","description":"Raise alerts when a token contains more than X SID-History entries (default X=2)."}],"live":true,"detection_strategies":["DET0136"],"techniques":["T1134.005"]}],"live":true,"version":"1.0","techniques":["T1134.005"]}],"sigma_rules":[{"id":"2632954e-db1c-49cb-9936-67d1ef1d17d2","title":"Addition of SID History to Active Directory Object","author":"Thomas Patzke, @atc_project (improvements)","status":"stable","level":"medium","date":"2017-02-19","modified":null,"description":"An attacker can use the SID history attribute to gain additional privileges.","references":["https://adsecurity.org/?p=1772"],"logsource":{"product":"windows","service":"security"},"tags":["attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1134.005"],"path":"rules/windows/builtin/security/win_security_susp_add_sid_history.yml","techniques":["T1134.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}