March 4, 2023, 12:56 p.m. | /u/vyasarvenkat

Malware Analysis & Reports www.reddit.com

Hello All,

I am trying to design a use-case for above technique. I have followed the below link [https://adsecurity.org/?p=1772](https://adsecurity.org/?p=1772) to execute the mimikatz 2.2 tool to perform sid-history injection and checked any event id 4765 , 4766 is getting generated in my AD but unfortunately MISC::AddSid module is not found in mimikatz 2.2.

I am not sure but I heard that sid history injection won't be able to perform in windows server 2016 and above.

Please let me know is …

access access token hello history injection malware manipulation server sid token windows windows server

Information Security Engineers

@ D. E. Shaw Research | New York City

Senior Cybersecurity Technical Delivery Manager

@ MUFG | London Ropemaker place

Junior consultant-Technology Risk

@ EY | Bratislava, SK, 811 02

Director of Security Engineering, Information Security

@ Illumio | Sunnyvale, California

Cyber Analyst II 03396 NWG

@ North Wind Group | KNOXVILLE, TN

CRIT Information Security Officer (f/m/d)

@ Deutsche Börse | Frankfurt am Main, DE