Compliance Node Overview
MITRE ATT&CK T1134.001 (Token Impersonation/Theft) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using DuplicateToken or DuplicateTokenEx. The token can then be used with ImpersonateLoggedOnUser to allow the calling thread to impersonate a logged on user's security context, or with SetThreadToken to assign the impersonated token to a thread. Affected platforms: Windows. MITRE-documented mitigations include M1018 User Account Management, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CM-05, CM-06, IA-02, IA-13.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1134/001/
SHA-256 integrity: ff733e74bf81d698ce20b54a923d7ba2849a6d66bf8e079f96ae8673191e20df
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1134.001: Token Impersonation/Theft (https://attack.mitre.org/techniques/T1134/001/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access