Fake system root directory creation
Detects attempts to create a fake or malformed Windows system root directory by a unprivileged process, which may indicate exploitation of path confusion vulnerabilities for privilege escalation.
- Platform: Windows
- Severity: High
- MITRE Tactic: Privilege Escalation
- MITRE Techniques: T1068