MITRE ATT&CK Technique
T1134.002Create Process with Token
- First Reported
- Sep 28, 2026
- Latest Reported
- Sep 28, 2026
Official Description
Adversaries may create a new process with an existing token to escalate privileges and bypass access controls. Processes can be created with the token and resulting security context of another user using features such as <code>CreateProcessWithTokenW</code> and <code>runas</code>.(Citation: Microsoft RunAs)
Creating processes with a token not associated with the current user may require the credentials of the target user, specific privileges to impersonate that user, or access to the token to be used. For example, the token could be duplicated via [Token Impersonation/Theft](https://attack.mitre.org/techniques/T1134/001) or created via [Make and Impersonate Token](https://attack.mitre.org/techniques/T1134/003) before being used to create a process.
While this technique is distinct from [Token Impersonation/Theft](https://attack.mitre.org/techniques/T1134/001), the techniques can be used in conjunction where a token is duplicated and then used to create a new process.
Creating processes with a token not associated with the current user may require the credentials of the target user, specific privileges to impersonate that user, or access to the token to be used. For example, the token could be duplicated via [Token Impersonation/Theft](https://attack.mitre.org/techniques/T1134/001) or created via [Make and Impersonate Token](https://attack.mitre.org/techniques/T1134/003) before being used to create a process.
While this technique is distinct from [Token Impersonation/Theft](https://attack.mitre.org/techniques/T1134/001), the techniques can be used in conjunction where a token is duplicated and then used to create a new process.
- Tactics
- Stealth, Privilege Escalation
- Platforms
- Windows
- Parent Technique
- T1134 · Access Token Manipulation
- MITRE Version
- 2.0
- Last Modified
- May 12, 2026
Reported Context (1)
- Threat actors used the duplicated service-account token to respawn the implant via CreateProcessAsUser. PaperCut Zero-Days Used to Deploy AdaptixC2 and Compromise an Education Customer’s Domain
CVE (2)
Malware (1)
MITRE ATT&CK (18)
Vendors (2)
Products (3)
Tools (8)
Industries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.