mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
25 lines
1.1 KiB
YAML
25 lines
1.1 KiB
YAML
name: Windows Privilege Escalation
|
|
id: 644e22d3-598a-429c-a007-16fdb802cae5
|
|
version: 2
|
|
date: '2020-02-04'
|
|
description: Monitor for and investigate activities that may be associated with a
|
|
Windows privilege-escalation attack, including unusual processes running on endpoints,
|
|
modified registry keys, and more.
|
|
narrative: 'Privilege escalation is a "land-and-expand" technique, wherein an adversary
|
|
gains an initial foothold on a host and then exploits its weaknesses to increase
|
|
his privileges. The motivation is simple: certain actions on a Windows machine--such
|
|
as installing software--may require higher-level privileges than those the attacker
|
|
initially acquired. By increasing his privilege level, the attacker can gain the
|
|
control required to carry out his malicious ends. This Analytic Story provides searches
|
|
to detect and investigate behaviors that attackers may use to elevate their privileges
|
|
in your environment.'
|
|
author: David Dorsey, Splunk
|
|
type: ESCU
|
|
references:
|
|
- https://attack.mitre.org/tactics/TA0004/
|
|
tags:
|
|
analytics_story: Windows Privilege Escalation
|
|
usecase: Advanced Threat Detection
|
|
category:
|
|
- Adversary Tactics
|