> Windows Syscalls
Back to ATT&CK index
T1134.002sub-technique

Create Process with Token

View on attack.mitre.org

3 syscalls implement this technique