Log sources › ETW:Token
ETW:Token
Inverted view: what can be detected if this is the log you have. Windows
2
channels
2
analytics
2
techniques
1
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
api_call: DuplicateTokenEx, ImpersonateLoggedOnUser, SetThreadToken |
DC0021 OS API Execution | AN1324 | 1 |
token_analysis: API calls such as DuplicateTokenEx or ImpersonateLoggedOnUser |
DC0021 OS API Execution | AN0786 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1134 Access Token Manipulation | stealth, privilege escalation | 4 | 0 |
| T1134.001 Token Impersonation/Theft | stealth, privilege escalation | 9 | 1 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway | T1134.001 | Mapped |