Suspicious registry symbolic link creation

Detects the creation of registry symbolic links, a technique that allows attackers to redirect registry key lookups to arbitrary locations within the registry hive. Adversaries abuse this mechanism to manipulate the registry namespace and influence how privileged processes or system services resolve registry paths, potentially enabling privilege escalation without exploiting a traditional code vulnerability.

Volver a todas las reglas