Possible Token Manipulation via NewCredentials Logon Type 9

PremiumReviewedSigma · Medium · v1
Product
windows
Service
security
Author
HuntRule
Published
2026-09-20
Updated
2026-09-20

ATT&CK techniques

Priv Esc → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects Windows Security event 4624 with logon type 9 NewCredentials, the telemetry produced by access token manipulation methods such as runas netonly and MakeToken described by Elastic. This logon type creates a process whose network identity differs from the local user which adversaries leverage for pass-the-hash style lateral movement. Reviewing the account process and target of these logons helps separate benign administrative use from abuse.

Related detections9 linkedT1550.002 — drag to rearrange
Suspicious Registry Modification Disabling RestrictedAdmin Mode (via process_creation)
Suspicious Lateral Movement via Invoke-WMIExec or Invoke-SMBExec (via ps_script)
Windows LsaSrv Events Indicating NTLMv1 Logon Between Client and Server
Windows PUA AdvancedRun.exe Execution
Windows: AdvancedRun executed with RunAs IDs under high-privilege service accounts
Windows getsystem via Meterpreter/Cobalt Strike when services.exe starts a likely privilege escalation command
Windows: Child Process Spawned with SYSTEM Integrity by LOCAL/NETWORK SERVICE Parent
Windows Pass-the-Hash Activity via Security Event 4624 (LogonType 3 or 9)
Windows NTLM authentication events (Event ID 8002)
Possible Token Manipulation via NewCredentials Logon Type 9
Pivot detection · T1550.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.