For the complete documentation index, see llms.txt. This page is also available as Markdown.

User added SID History to an account

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Hour

Required Data

Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Analytics

ATT&CK Tactic

Privilege Escalation (TA0004), Stealth (TA0005)

ATT&CK Technique

Access Token Manipulation: SID-History Injection (T1134.005)

Severity

Informational

Description

A user added SID history to an account. This may be indicative of a user's migration between domains or a SID injection attack.

Attacker's Goals

Adversaries may use SID history to escalate privileges and bypass access controls.

Investigative actions

  • Verify if migration between domains was involved.

  • Search for suspicious actions by the user, such as forged Kerberos tickets.

Variations

Suspicious SID History Addition

Synopsis

Field
Value

ATT&CK Tactic

Privilege Escalation (TA0004), Stealth (TA0005)

ATT&CK Technique

Access Token Manipulation: SID-History Injection (T1134.005)

Severity

Medium

Description

A user added SID history to an account. The account was not migrated between domains, which may indicate a SID injection attack.

Attacker's Goals

Adversaries may use SID history to escalate privileges and bypass access controls.

Investigative actions

  • Verify if migration between domains was involved.

  • Search for suspicious actions by the user, such as forged Kerberos tickets.

Was this helpful?