Fake system root directory creation
Detects attempts to create a fake or malformed Windows system root directory by a unprivileged process, which may indicate exploitation of path confusion vulnerabilities for privilege escalation.
- Plataforma: Windows
- Severidad: High
- Táctica MITRE: Escalada de privilegios
- Técnicas MITRE: T1068