Fake system root environment variable manipulation
Identifies attempts to manipulate user-scoped Windows directory registry values to point to non-standard locations, a technique commonly abused to fake the system root directory and enable privilege escalation.
- Plataforma: Windows
- Severidad: High
- Táctica MITRE: Escalada de privilegios
- Técnicas MITRE: T1068