>
Windows Syscalls
Syscalls
Version map
ATT&CK
Malware
Generator
Syscall graph
Blog
Language
EN — English
FR — Français
ES — Español
DE — Deutsch
← Back to ATT&CK index
T1069
Permission Groups Discovery
View on attack.mitre.org →
1 syscalls implement this technique
NtQuerySecurityObject
Retrieves a self-relative SECURITY_DESCRIPTOR from any kernel object exposed via a handle.