<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Secondary-Logon - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/secondary-logon/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 19:07:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/secondary-logon/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Abuse of Windows Secondary Logon Service for Privilege Escalation</title><link>https://feed.craftedsignal.io/briefs/2026-10-secondary-logon-abuse/</link><pubDate>Thu, 08 Oct 2026 19:07:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-secondary-logon-abuse/</guid><description>Adversaries may perform local privilege escalation by abusing the Windows Secondary Logon service to spawn processes with alternate user credentials.</description><content:encoded><![CDATA[<p>The Windows Secondary Logon service (seclogon) is designed to allow users to execute processes under alternate credentials, a feature frequently leveraged for legitimate administrative tasks. However, this functionality can be abused by adversaries to achieve local privilege escalation. By invoking the service to create a process with an alternate security token, an attacker can bypass access controls and execute code with higher privileges than their current session.</p>
<p>This technique is often used as a post-exploitation mechanism to transition from a low-privileged account to a high-privileged one. Defenders should monitor for successful authentication events linked to the Secondary Logon service, specifically looking for process creation activities associated with the resulting TargetLogonId. This pattern is indicative of potential privilege escalation attempts when observed in conjunction with unexpected process execution.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains initial access to the system through a low-privileged account.</li>
<li>Attacker prepares malicious payloads or tools to be executed under a target privileged context.</li>
<li>Attacker invokes the Secondary Logon service (seclogon) using the RunAs API or equivalent command-line tools.</li>
<li>The system triggers a local authentication event where the svchost.exe process handles the request via seclogon.</li>
<li>The service validates the alternate credentials and generates a new, unique Logon ID for the session.</li>
<li>The adversary launches a new process (e.g., cmd.exe, powershell.exe) linked to this new TargetLogonId.</li>
<li>The process executes with the elevated or alternate user security context, effectively completing the privilege escalation.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an adversary to execute arbitrary code with elevated privileges, potentially leading to full system compromise, exfiltration of sensitive data, or persistence establishment. This impact is significant in environments where administrative credentials can be harvested or abused via this service.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Enable 'Audit Logon' and 'Audit Process Creation' policies on all Windows endpoints to capture the necessary telemetry.</li>
<li>Deploy the provided Sigma rule to detect the sequence of Secondary Logon authentication followed by process creation.</li>
<li>Review and baseline administrative tasks that legitimately utilize the Secondary Logon service to reduce false positives.</li>
<li>Investigate any process creation events linked to 'seclogo*' logon processes that originate from unexpected parent processes.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>privilege-escalation</category><category>windows</category><category>secondary-logon</category></item></channel></rss>