Analytics BIOC Informational

User added SID History to an account

A user added SID history to an account. This may be indicative of a user's migration between domains or a SID injection attack.

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004) Defense Evasion (TA0005)
ATT&CK techniques: Access Token Manipulation: SID-History Injection (T1134.005)
Attacker's goals:

Adversaries may use SID history to escalate privileges and bypass access controls.

Investigative actions:

Verify if migration between domains was involved. Search for suspicious actions by the user, such as forged Kerberos tickets.

Test period:
N/A (single event)
Deduplication:
1 Hour
1 variation:
  • Suspicious SID History Addition Medium (parent: Informational)