Files
splunk-security_content/stories/windows_privilege_escalation.yml
Patrick Bareiss 7cbc9a9ba6 WIP
2020-04-30 10:34:18 +02:00

25 lines
1.1 KiB
YAML

name: Windows Privilege Escalation
id: 644e22d3-598a-429c-a007-16fdb802cae5
version: 2
date: '2020-02-04'
description: Monitor for and investigate activities that may be associated with a
Windows privilege-escalation attack, including unusual processes running on endpoints,
modified registry keys, and more.
narrative: 'Privilege escalation is a "land-and-expand" technique, wherein an adversary
gains an initial foothold on a host and then exploits its weaknesses to increase
his privileges. The motivation is simple: certain actions on a Windows machine--such
as installing software--may require higher-level privileges than those the attacker
initially acquired. By increasing his privilege level, the attacker can gain the
control required to carry out his malicious ends. This Analytic Story provides searches
to detect and investigate behaviors that attackers may use to elevate their privileges
in your environment.'
author: David Dorsey, Splunk
type: ESCU
references:
- https://attack.mitre.org/tactics/TA0004/
tags:
analytics_story: Windows Privilege Escalation
usecase: Advanced Threat Detection
category:
- Adversary Tactics