Access Token Theft and Manipulation Attacks – A Door to Local Privilege Escalation
ID: 931fdf3d-fad2-5560-a2b4-8dac416449c6
STIX ID: report--931fdf3d-fad2-5560-a2b4-8dac416449c6
Feed Name: McAfee Labs Blog
Threat Score
This McAfee technical brief explains how attackers and malware abuse Windows process access tokens—via theft, duplication, and impersonation—to escalate privileges and perform stealthy lateral movement; it outlines attack paths, APIs used, mitigation bypasses (e.g., UAC), and references detection guidance including on-access scanning and a YARA rule with a link to the full technical analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
