User added SID History to an account
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Privilege Escalation (TA0004), Stealth (TA0005)
ATT&CK Technique
Access Token Manipulation: SID-History Injection (T1134.005)
Severity
Informational
Description
A user added SID history to an account. This may be indicative of a user's migration between domains or a SID injection attack.
Attacker's Goals
Adversaries may use SID history to escalate privileges and bypass access controls.
Investigative actions
Verify if migration between domains was involved.
Search for suspicious actions by the user, such as forged Kerberos tickets.
Variations
Was this helpful?
