Potential privilege elevation via arbitrary section creation

Identifies potential privilege escalation attempts where a non-SYSTEM process creates symbolic links targeting object manager namespaces specific to memory section objects followed by the creation of a SYSTEM process. This behavior may indicate exploitation of arbitrary object directory or section creation vulnerabilities that abuse symbolic link redirection to manipulate privileged operations and gain elevated execution.

Back to all rules