Privilege Escalation - Windows

  1. T1548: Abuse Elevation Control Mechanism

  2. T1134: Access Token Manipulation

  3. T1055: Process Injection

  4. T1068: Exploitation for Privilege Escalation

  5. T1078: Valid Accounts

  6. T1547: Boot or Logon Autostart Execution

  7. T1546: Event Triggered Execution

  8. T1556: Modify Authentication Process

  9. T1574: Hijack Execution Flow

  10. T1037: Boot or Logon Initialization Scripts

Last updated