Analytics BIOC
Informational
✕
User added SID History to an account
A user added SID history to an account. This may be indicative of a user's migration between domains or a SID injection attack.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004) Defense Evasion (TA0005)
ATT&CK techniques: Access Token Manipulation: SID-History Injection (T1134.005)
Attacker's goals:
Adversaries may use SID history to escalate privileges and bypass access controls.
Investigative actions:
Verify if migration between domains was involved. Search for suspicious actions by the user, such as forged Kerberos tickets.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Hour
1 variation:
- Suspicious SID History Addition Medium (parent: Informational)