{"id":"T1134","name":"Access Token Manipulation","url":"https://attack.mitre.org/techniques/T1134","tactics":["stealth","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0283","stix_id":"x-mitre-detection-strategy--774bbba8-45c2-403d-a445-3a64b3679faf","name":"Behavior-chain detection for T1134 Access Token Manipulation on Windows","url":"https://attack.mitre.org/detectionstrategies/DET0283","analytics":[{"id":"AN0786","stix_id":"x-mitre-analytic--c4cabd45-86a2-4842-9171-dff93f6ac737","name":"Analytic 0786","description":"Detection of suspicious token manipulation chains: use of token-related APIs (e.g., LogonUser, DuplicateTokenEx) or commands (runas) → spawning of a new process under a different security context (e.g., SYSTEM) → mismatched parent-child process lineage or anomalies in Event Tracing for Windows (ETW) token/PPID data → abnormal lateral or privilege escalation activity.","url":"https://attack.mitre.org/detectionstrategies/DET0283#AN0786","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4672, 4634","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"ETW:Token","channel":"token_analysis: API calls such as DuplicateTokenEx or ImpersonateLoggedOnUser","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"etw-token"},{"name":"WinEventLog:Security","channel":"EventCode=5136","data_component":"DC0066","data_component_name":"Active Directory Object Modification","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlation time between suspicious API usage, runas, and process creation (e.g., 5–10m)."},{"field":"AllowedServiceAccounts","description":"Whitelist of service accounts permitted to spawn SYSTEM-level processes."},{"field":"KnownAdminTools","description":"Legitimate administrative utilities that trigger token changes."},{"field":"ParentProcessAnomalyThreshold","description":"Deviation threshold for PPID mismatches detected via ETW."}],"live":true,"detection_strategies":["DET0283"],"techniques":["T1134"]}],"live":true,"version":"1.0","techniques":["T1134"]}],"sigma_rules":[{"id":"2617e7ed-adb7-40ba-b0f3-8f9945fe6c09","title":"Suspicious SYSTEM User Process Creation","author":"Florian Roth (Nextron Systems), David ANDRE (additional keywords)","status":"test","level":"high","date":"2021-12-20","modified":"2025-10-19","description":"Detects a suspicious process creation as SYSTEM user (suspicious program or command line parameter)","references":["Internal Research","https://tools.thehacker.recipes/mimikatz/modules"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.privilege-escalation","attack.stealth","attack.t1134","attack.t1003","attack.t1027"],"path":"rules/windows/process_creation/proc_creation_win_susp_system_user_anomaly.yml","techniques":["T1134","T1003","T1027"],"cves":[]},{"id":"7b14c76a-c602-4ae6-9717-eff868153fc0","title":"HackTool - NoFilter Execution","author":"Stamatis Chatzimangou (st0pp3r)","status":"test","level":"high","date":"2024-01-05","modified":null,"description":"Detects execution of NoFilter, a tool for abusing the Windows Filtering Platform for privilege escalation via hardcoded policy name indicators\n","references":["https://github.com/deepinstinct/NoFilter/blob/121d215ab130c5e8e3ad45a7e7fcd56f4de97b4d/NoFilter/Consts.cpp","https://github.com/deepinstinct/NoFilter","https://www.deepinstinct.com/blog/nofilter-abusing-windows-filtering-platform-for-privilege-escalation","https://x.com/_st0pp3r_/status/1742203752361128162?s=20"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.stealth","attack.t1134","attack.t1134.001"],"path":"rules/windows/builtin/security/win_security_hktl_nofilter.yml","techniques":["T1134","T1134.001"],"cves":[]},{"id":"d2b7a134-9c3e-4f8a-b56d-e0c1f8a29b47","title":"Suspicious Cross-User Process Spawn","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2026-07-23","modified":null,"description":"Detects suspicious spawning of a process under a different user context than the parent process.\nProcesses such as notepad.exe, calculator etc. are generally spawned under the same user context and\nalso they are often targeted as sacrificial process or decoy process to check successful privilege escalation.\n","references":["https://github.com/MSNightmare/LegacyHive","https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.stealth","attack.t1055","attack.t1134"],"path":"rules/windows/process_creation/proc_creation_win_susp_cross_user_process_spawn.yml","techniques":["T1055","T1134"],"cves":[]},{"id":"e3c6d245-7b8f-4e2a-c17f-a9d0e5b38f62","title":"Potentially Suspicious Explicit Credential Local Logon","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2026-07-23","modified":null,"description":"Detects potentially suspicious explicit credential logon events where the user\nis trying to logon with explicit credentials (username and password) that are\ndifferent from the current user context. It might indicate an attacker attempting\nto escalate privileges after obtaining credentials for a different user account.\n","references":["https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648","https://github.com/MSNightmare/LegacyHive"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.stealth","attack.t1134","attack.t1134.003"],"path":"rules/windows/builtin/security/win_security_explicit_credential_local_logon.yml","techniques":["T1134","T1134.003"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}