Elastic high stable eql
Potential Escalation via Vulnerable MSI Repair
Identifies when a browser process navigates to the Microsoft Help page followed by spawning an elevated process. This may indicate a successful exploitation for privilege escalation abusing a vulnerable Windows Installer repair setup.
Detection Logic
process where event.type == "start" and host.os.type == "windows" and
user.domain : ("NT AUTHORITY", "AUTORITE NT", "AUTORIDADE NT") and
process.parent.name : ("chrome.exe", "msedge.exe", "brave.exe", "whale.exe", "browser.exe", "dragon.exe", "vivaldi.exe",
"opera.exe", "iexplore", "firefox.exe", "waterfox.exe", "iexplore.exe", "tor.exe", "safari.exe") and
process.parent.command_line : "*go.microsoft.com*" Field Validations
Loading…
Comments (0)
Loading comments...