Product
high
advisory
Local Privilege Escalation in Sophos Endpoint
1 TTPA local privilege escalation vulnerability in Sophos Endpoint allows an authenticated local attacker to execute arbitrary code with administrative privileges.
Endpoint
privilege-escalation
windows
security-advisory
1t
low
advisory
Unusual Process Spawned by a User Detected by ML
2 TTPsA machine learning job from Elastic's ProblemChild integration detects suspicious Windows processes, classified as malicious by a supervised ML model and anomalous due to unusual user contexts identified by an unsupervised ML model, indicating potential misuse of LOLbins or masquerading tactics for defense evasion.
problemchild +6
Endpoint
Windows
Elastic Defend
Elastic Endgame
Living off the Land Attack Detection
ML
Machine Learning
Defense Evasion
+1
2t