Cross-source coverage
T1178 / ATT&CK
SID-History Injection
ATT&CK has retired this technique. Rules still tag it; the current id is T1134.005 Access Token Manipulation: SID-History Injection.
1 rule across 1 source.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
The Windows security identifier (SID) is a unique value that identifies a user or group account. SIDs are used by Windows security in both security descriptors and access tokens. An account can hold additional SIDs in the SID-History Active Directory attribute, allowing inter-operable account migration between domains (e.g., all values in SID-History are included in access tokens).
Adversaries may use this mechanism for privilege escalation. With Domain Administrator (or equivalent) rights, harvested or well-known SID values may be inserted into SID-History to enable impersonation of arbitrary users/groups such as Enterprise Administrators. This manipulation may result in elevated access to local resources and/or access to otherwise inaccessible domains via lateral movement techniques such as Remote Services, Windows Admin Shares, or Windows Remote Management.
- Tactics
- Privilege Escalation
- Platforms
- Windows
- Telemetry
- —
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| addition_of_sid_history_to_active_directory_object | Undefined | YARA-L |