> For the complete documentation index, see [llms.txt](https://windows.dfirhandbook.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://windows.dfirhandbook.com/windows-dfir-and-mittr/privilege-escalation.md).

# Privilege Escalation

* T1548: Abuse Elevation Control Mechanism
* T1134: Access Token Manipulation
* T1055: Process Injection
* T1068: Exploitation for Privilege Escalation
* T1078: Valid Accounts
* T1547: Boot or Logon Autostart Execution
* T1546: Event Triggered Execution
* T1556: Modify Authentication Process
* T1574: Hijack Execution Flow
* T1037: Boot or Logon Initialization Scripts
