threatengine.sh
· ··:··
Sign in
free plan Dashboard Stack Monitoring Notifications Watchlist Account & tokens API docs Pricing Sign out
Home/ CVE-2026-11624/ Attack path

Attack path: Access Token Manipulation

Kill-chain expansion via actor co-occurrence analysis  ·  16 techniques  ·  9 detectable  ·  7 detection gaps
Entry point: CVE-2026-11624 T1134
Other
T1027.007
Dynamic API Resolution
× no rule
4.4x lift
T1562.006
Indicator Blocking
× no rule
4.4x lift
Stealth
T1134
Access Token Manipulation
✓ sigma
999.0x lift
Execution
T1559.002
Dynamic Data Exchange
✓ sigma
4.4x lift
Persistence
T1037.003
Network Logon Script
× no rule
4.4x lift
T1137.006
Add-ins
✓ sigma
4.4x lift
Priv Escalation
T1546.001
Change Default File Associatio…
✓ sigma
4.4x lift
T1546.015
Component Object Model Hijacki…
✓ sigma
4.4x lift
T1134.001
Token Impersonation/Theft
✓ sigma
4.4x lift
T1546.011
Application Shimming
✓ sigma
4.4x lift
T1134.002
Create Process with Token
✓ sigma
4.4x lift
Collection
T1213.006
Databases
× no rule
4.4x lift
T1560.002
Archive via Library
× no rule
4.4x lift
C2
T1008
Fallback Channels
✓ sigma
4.4x lift
T1104
Multi-Stage Channels
× no rule
4.4x lift
Impact
T1488
Disk Content Wipe
× no rule
4.4x lift
Entry point (from CVE) Detection rule available Detection gap - potential blind spot Lift = how strongly this technique co-occurs with the entry point across shared threat actors (1x = expected, 5x = highly distinctive)
Hunt package
All 16 techniques in this chain - Sigma rules, Atomic tests, and detection gaps in one view.
Sigma rules Full technique
SOC and Response
CVE triage
Stack monitoring
Am I affected
IOC triage
KEV catalog
Recently exploited
Daily brief
Change tracking
Detection Engineering
Coverage workspace
Detection coverage
Coverage check
Telemetry ceiling
SIEM query builder
Sigma rules
SIEM rules
YARA rules
Network rules
D3FEND
Threat Hunting
Threat actors
ATT&CK techniques
Attack paths
Indicators
Atomic tests
Red Team and Pentest
Exploitability triage
Recon pack
Attack paths
CAPEC patterns
Adversary emulation
Compliance and GRC
Framework mapping
Control assessment
Audit view
Atlas Search Threat actors Techniques Tools & malware CWE CAPEC KEV catalog Package vulns
About All capabilities Pricing API docs Live status Privacy policy Terms of service
threatengine.sh
Are you sure?
We use one first-party cookie to remember how you found us, only if you allow it. Everything the site needs to work uses essential cookies. See our privacy policy.