kevmap

Log sources › ETW:Token

ETW:Token

Inverted view: what can be detected if this is the log you have. Windows

2
channels
2
analytics
2
techniques
1
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
api_call: DuplicateTokenEx, ImpersonateLoggedOnUser, SetThreadToken DC0021 OS API Execution AN1324 1
token_analysis: API calls such as DuplicateTokenEx or ImpersonateLoggedOnUser DC0021 OS API Execution AN0786 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1134 Access Token Manipulationstealth, privilege escalation40
T1134.001 Token Impersonation/Theftstealth, privilege escalation91

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway T1134.001 Mapped