Potential privilege escalation via DeadPotato exploit
Detects potential privilege escalation activity consistent with the DeadPotato exploit. Attackers can abuse the DCOM RPCSS service flaw to start an elevated process allowing unrestricted access over the machine for critical operations to be freely performed.
- Platform: Windows
- Severity: High
- MITRE Tactic: Privilege Escalation
- MITRE Techniques: T1068