Tag
high
advisory
Detection of Potential WinAPI Calls via PowerShell Scripts for Evasion
1 rule 3 TTPsThis brief details the detection of PowerShell scripts that leverage Windows API functions, a common technique employed by threat actors for process injection, token manipulation, and other evasive malicious activities to bypass traditional security controls.
powershell
winapi
evasion
process-injection
privilege-escalation
token-manipulation
endpoint
windows
1r
3t
medium
advisory
Unusual Process Performing NewCredentials Logon
2 rules 1 TTPAnomalous NewCredentials logon events triggered by uncommon processes may indicate access token manipulation for privilege escalation.
Windows
privilege-escalation
token-manipulation
2r
1t
medium
advisory
SeDebugPrivilege Enabled by a Suspicious Process
2 rules 1 TTPThe rule identifies a process running with a non-SYSTEM account that enables the SeDebugPrivilege privilege, which can be used by adversaries to debug and modify other processes to escalate privileges and bypass access controls.
Windows
privilege-escalation
token-manipulation
2r
1t