logo

Access Token Theft and Manipulation Attacks – A Door to Local Privilege Escalation

ID: 931fdf3d-fad2-5560-a2b4-8dac416449c6

STIX ID: report--931fdf3d-fad2-5560-a2b4-8dac416449c6

Feed Name: McAfee Labs Blog

Threat Score
55/100

Date Published: 2021-04-20

Date Updated: 2026-04-28

Author: Chintan Shah

...
...

This McAfee technical brief explains how attackers and malware abuse Windows process access tokens—via theft, duplication, and impersonation—to escalate privileges and perform stealthy lateral movement; it outlines attack paths, APIs used, mitigation bypasses (e.g., UAC), and references detection guidance including on-access scanning and a YARA rule with a link to the full technical analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.