BigHugger
sk Skill · mukul975

detecting-t1548-abuse-elevation-control-mechanism

Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry changes, integrity-level transitions, and parent-child process relationships via Sysmon and Windows Security events. Use when hunting privilege-escalation activity or validating elevation-abuse detection coverage.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
kqlwindows-securityelevation-controlmitre-t1548privilege-escalationPythonuac-bypassyamlsplthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python