Potential privilege escalation via DeadPotato exploit

Detects potential privilege escalation activity consistent with the DeadPotato exploit. Attackers can abuse the DCOM RPCSS service flaw to start an elevated process allowing unrestricted access over the machine for critical operations to be freely performed.

Back to all rules