Potential privilege escalation via phantom DLL hijacking

Identifies the loading of the phantom DLL that was previously dropped to the System directory. Adversaries may exploit this flow to escalate privileges by placing a custom version of the DLL and initiating the execution of an auto-elevated high integrity Windows native process.

Back to all rules