{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/secondary-logon/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows"],"_cs_severities":["medium"],"_cs_tags":["privilege-escalation","windows","secondary-logon"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eThe Windows Secondary Logon service (seclogon) is designed to allow users to execute processes under alternate credentials, a feature frequently leveraged for legitimate administrative tasks. However, this functionality can be abused by adversaries to achieve local privilege escalation. By invoking the service to create a process with an alternate security token, an attacker can bypass access controls and execute code with higher privileges than their current session.\u003c/p\u003e\n\u003cp\u003eThis technique is often used as a post-exploitation mechanism to transition from a low-privileged account to a high-privileged one. Defenders should monitor for successful authentication events linked to the Secondary Logon service, specifically looking for process creation activities associated with the resulting TargetLogonId. This pattern is indicative of potential privilege escalation attempts when observed in conjunction with unexpected process execution.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access to the system through a low-privileged account.\u003c/li\u003e\n\u003cli\u003eAttacker prepares malicious payloads or tools to be executed under a target privileged context.\u003c/li\u003e\n\u003cli\u003eAttacker invokes the Secondary Logon service (seclogon) using the RunAs API or equivalent command-line tools.\u003c/li\u003e\n\u003cli\u003eThe system triggers a local authentication event where the svchost.exe process handles the request via seclogon.\u003c/li\u003e\n\u003cli\u003eThe service validates the alternate credentials and generates a new, unique Logon ID for the session.\u003c/li\u003e\n\u003cli\u003eThe adversary launches a new process (e.g., cmd.exe, powershell.exe) linked to this new TargetLogonId.\u003c/li\u003e\n\u003cli\u003eThe process executes with the elevated or alternate user security context, effectively completing the privilege escalation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an adversary to execute arbitrary code with elevated privileges, potentially leading to full system compromise, exfiltration of sensitive data, or persistence establishment. This impact is significant in environments where administrative credentials can be harvested or abused via this service.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable 'Audit Logon' and 'Audit Process Creation' policies on all Windows endpoints to capture the necessary telemetry.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect the sequence of Secondary Logon authentication followed by process creation.\u003c/li\u003e\n\u003cli\u003eReview and baseline administrative tasks that legitimately utilize the Secondary Logon service to reduce false positives.\u003c/li\u003e\n\u003cli\u003eInvestigate any process creation events linked to 'seclogo*' logon processes that originate from unexpected parent processes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:07:53Z","date_published":"2026-10-08T19:07:53Z","id":"https://feed.craftedsignal.io/briefs/2026-10-secondary-logon-abuse/","summary":"Adversaries may perform local privilege escalation by abusing the Windows Secondary Logon service to spawn processes with alternate user credentials.","title":"Abuse of Windows Secondary Logon Service for Privilege Escalation","url":"https://feed.craftedsignal.io/briefs/2026-10-secondary-logon-abuse/"}],"language":"en","title":"CraftedSignal Threat Feed - Secondary-Logon","version":"https://jsonfeed.org/version/1.1"}