CPE
medium
advisory
Suspicious Child Processes of consent.exe
1 rule 3 TTPs 1 CVEDetection of unauthorized child process creation by the Windows UAC consent.exe binary, a common indicator of UAC bypass and privilege escalation activity.
Windows
privilege-escalation
uac-bypass
1r
3t
1c
high
advisory
Suspicious Microsoft Office Child Process Activity
1 rule 3 TTPs 1 CVEMicrosoft Office applications are frequently abused to spawn system processes to execute malicious code, download payloads, or facilitate privilege escalation.
Microsoft Office
1r
3t
1c
high
advisory
Potential Privilege Escalation via InstallerFileTakeOver (CVE-2021-41379)
2 rules 1 TTP 1 CVEThis rule detects potential exploitation of the InstallerTakeOver vulnerability (CVE-2021-41379), where successful exploitation allows an unprivileged user to escalate privileges to SYSTEM.
Edge
privilege-escalation
cve-2021-41379
windows
2r
1t
1c