Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1134.001

T1134.001Token Impersonation/Theft

T1134.001 — Token Impersonation/Theft is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 5 detection use cases covering it and 1 threat-intel article citing it.

Defense EvasionPrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
5Use cases
1Articles
0Sub-techniques
2Tactics

Use cases covering this technique (5)

Runas Execution in CommandLine ESCU actions · hunting P Windows Access Token Manipulation Winlogon Duplicate Token Handle ESCU actions · hunting P Windows Access Token Winlogon Duplicate Handle In Uncommon Path ESCU actions · hunting P Windows Handle Duplication in Known UAC-Bypass Binaries ESCU actions · hunting P [LLM] Non-browser process reading Chrome/Edge/Opera Login Data or Local State Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (1)