Privilege Escalation Detection Rules | Fibratus
Detection rules for Privilege Escalation (MITRE ATT&CK): UAC bypasses, token manipulation, rogue DLL hijacking, and scheduled task abuse.
Rules in this category
- Exploitation via Common Log File System
- Fake system root directory creation
- Fake system root environment variable manipulation
- Potential privilege elevation via arbitrary section creation
- Potential privilege escalation via DeadPotato exploit
- Potential privilege escalation via elevated IFileOperation COM interface
- Potential privilege escalation via phantom DLL hijacking
- Suspicious child process integrity level
- Suspicious registry symbolic link creation
- UAC bypass via assembly Native Image Cache hijack
- UAC bypass via CDSSync scheduled task hijack
- UAC bypass via command handler hijacking
- UAC bypass via Control Panel applet execution hijack
- UAC bypass via DiskCleanup scheduled task hijack
- UAC bypass via DLL hijack from Windows Media player directory
- UAC bypass via .NET Code Profiler DLL Hijack
- UAC bypass via elevated Internet Explorer add-on installer COM interface
- UAC bypass via ICMLuaUtil COM interface
- UAC bypass via NTFS junction DLL hijacking
- UAC bypass via Program Compatibility Assistant scheduled task hijack
- UAC bypass via RequestTrace scheduled task hijack
- UAC bypass via rouge MMC snap-in
- UAC bypass via trusted Windows directory masquerading
- Untrusted DLL loaded from masqueraded Windows directory