logo

Understanding and Defending Against Access Token Theft: Finding Alternatives to winlogon.exe

ID: 7ca1dc16-10b2-50c3-bf21-db1a272cba26

STIX ID: report--7ca1dc16-10b2-50c3-bf21-db1a272cba26

Feed Name: SpecterOps Blog

Date Published: 2019-10-01

Date Updated: 2026-04-30

Author: Justin Bui

...
...

This post examines the Windows access token manipulation technique (MITRE ATT&CK T1134) to elevate from local admin to SYSTEM by abusing APIs such as `OpenProcess`, `OpenProcessToken`, `DuplicateTokenEx`, and `CreateProcessWithTokenW`, with `winlogon.exe` and other SYSTEM processes as targets. It outlines detection using SACL-based auditing and Windows Security Log EIDs 4656 and 4663, explains why some processes are exploitable (TokenOwner differences) while others are constrained by Protected Process Light, and provides a tested list of processes where SYSTEM tokens can be impersonated with required access rights.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.