Cross-source coverage
T1178 / ATT&CK
SID-History Injection
ATT&CK has retired this technique. Rules still tag it; the current id is T1134.005 Access Token Manipulation: SID-History Injection.
0 rules across 0 sources.
1 deprecated hidden · include
From MITRE ATT&CK 19.2
The Windows security identifier (SID) is a unique value that identifies a user or group account. SIDs are used by Windows security in both security descriptors and access tokens. An account can hold additional SIDs in the SID-History Active Directory attribute, allowing inter-operable account migration between domains (e.g., all values in SID-History are included in access tokens).
Adversaries may use this mechanism for privilege escalation. With Domain Administrator (or equivalent) rights, harvested or well-known SID values may be inserted into SID-History to enable impersonation of arbitrary users/groups such as Enterprise Administrators. This manipulation may result in elevated access to local resources and/or access to otherwise inaccessible domains via lateral movement techniques such as Remote Services, Windows Admin Shares, or Windows Remote Management.
- Tactics
- Privilege Escalation
- Platforms
- Windows
- Telemetry
- —
No live rules cover this technique. 1 deprecated rule is hidden.