1200KM / simulation
T1134.001 Token Impersonation/Theft — Attack Simulation
Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread. An adversary…
Technique description
Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread. An adversary…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- `SeDebugPrivilege` token duplication
Procedure 34f0a430-9d04-4d98-bcb5-1989f14719f0; elevation required; cleanup not declared. Not executed or individually validated.
- Launch NSudo Executable
Procedure 7be1bc0f-d8e5-4345-9333-f5f67d742cb9; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Named pipe client impersonation
Procedure 90db9e27-8e7c-4c04-b602-a45927884966; elevation required; cleanup not declared. Not executed or individually validated.
- Bad Potato
Procedure 9c6d799b-c111-4749-a42f-ec2f8cb51448; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Juicy Potato
Procedure f095e373-b936-4eb4-8d22-f47ccbfbe64a; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.