Abuse of Windows Secondary Logon Service for Privilege Escalation
Adversaries may perform local privilege escalation by abusing the Windows Secondary Logon service to spawn processes with alternate user credentials.
The Windows Secondary Logon service (seclogon) is designed to allow users to execute processes under alternate credentials, a feature frequently leveraged for legitimate administrative tasks. However, this functionality can be abused by adversaries to achieve local privilege escalation. By invoking the service to create a process with an alternate security token, an attacker can bypass access controls and execute code with higher privileges than their current session.
This technique is often used as a post-exploitation mechanism to transition from a low-privileged account to a high-privileged one. Defenders should monitor for successful authentication events linked to the Secondary Logon service, specifically looking for process creation activities associated with the resulting TargetLogonId. This pattern is indicative of potential privilege escalation attempts when observed in conjunction with unexpected process execution.
Attack Chain
- Attacker gains initial access to the system through a low-privileged account.
- Attacker prepares malicious payloads or tools to be executed under a target privileged context.
- Attacker invokes the Secondary Logon service (seclogon) using the RunAs API or equivalent command-line tools.
- The system triggers a local authentication event where the svchost.exe process handles the request via seclogon.
- The service validates the alternate credentials and generates a new, unique Logon ID for the session.
- The adversary launches a new process (e.g., cmd.exe, powershell.exe) linked to this new TargetLogonId.
- The process executes with the elevated or alternate user security context, effectively completing the privilege escalation.
Impact
Successful exploitation allows an adversary to execute arbitrary code with elevated privileges, potentially leading to full system compromise, exfiltration of sensitive data, or persistence establishment. This impact is significant in environments where administrative credentials can be harvested or abused via this service.
Recommendation
- Enable 'Audit Logon' and 'Audit Process Creation' policies on all Windows endpoints to capture the necessary telemetry.
- Deploy the provided Sigma rule to detect the sequence of Secondary Logon authentication followed by process creation.
- Review and baseline administrative tasks that legitimately utilize the Secondary Logon service to reduce false positives.
- Investigate any process creation events linked to 'seclogo*' logon processes that originate from unexpected parent processes.
Immediate actions
Enable Audit Logon and Audit Process Creation on Windows endpoints
Threat Hunt
Search for instances of seclogon activity followed by suspicious process execution
Data: Windows Event Logs 4624 and 4688
Detection coverage 1
Detect Process Creation via Secondary Logon
mediumDetects process creation events that follow a successful authentication via the Windows Secondary Logon service using TargetLogonId correlation.
Detection queries are available on the platform. Get full rules →