Tag
high
advisory
Service Security Descriptor Tampering via Sc.exe
1 rule 1 TTPAdversaries can exploit the Windows 'sc.exe' utility to modify service Discretionary Access Control Lists (DACLs) via the 'sdset' command, facilitating privilege escalation and persistence by granting unauthorized service access.
privilege-escalation
persistence
windows
security-descriptor
sc-exe
1r
1t
high
threat
Windows Audit Policy Security Descriptor Tampering via Auditpol
2 rules 1 TTPDetection of `auditpol.exe` execution with arguments to modify the audit policy security descriptor, indicative of defense evasion by adversaries aiming to limit audit logging.
Splunk Enterprise +2
auditpol
security descriptor
defense evasion
windows
2r
1t