Adversaries may use SID-History Injection to escalate privileges and bypass access controls. The Windows security identifier (SID) is a unique value that identifies a user or group account. SIDs are used by Windows security in both security descriptors and access tokens. (Citation: Microsoft SID) An account can hold additional SIDs in the SID-History Active Directory attribute (Citation: Microsoft SID-History Attribute), allowing inter-operable account migration between domains (e.g., all values in SID-History are included in access tokens). With Domain Administrator (or equivalent) rights, harvested or well-known SID values (Citation: Microsoft Well Known SIDs Jun 2017) may be inserted into SID-History to enable impersonation of arbitrary users/groups such as Enterprise Administrators. This manipulation may result in elevated access to local resources and/or access to otherwise inaccessible domains via lateral movement techniques such as [Remote Services](https://attack.mitre.org/techniques/T1021), [SMB/Windows Admin Shares](https://attack.mitre.org/techniques/T1021/002), or [Windows Remote Management](https://attack.mitre.org/techniques/T1021/006).

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Active Directory Configuration
is blocked by Behavior-chain detection for T1134.005 Access Token Manipulation: SID-History Injection (Windows)
is blocked by Secure Baseline Configurations
is blocked by Use of External Technology Assets, Applications and/or Services (TAAS)
is blocked by Separation of Duties (SoD)
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Secure Engineering Principles
is blocked by Security Function Isolation
is blocked by Technology Development & Acquisition
is blocked by Developer Architecture & Design
is blocked by Security, Compliance & Resilience Testing Throughout Development
Impressum Deutsch Englisch