Sagan critical stable other

[CROWDSTRIKE] Privilege Escalation Tactic Catchall

[CROWDSTRIKE] Privilege Escalation Tactic Catchall

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[CROWDSTRIKE] Privilege Escalation Tactic Catchall"; program:CrowdStrike; content:"tactic=Privilege Escalation"; content:!"A user received new privileges"; content:!"msg=An authentication protocol was used in an unusual manner"; content:!"IdpDetectionSummaryEvent"; content:!"FcsIoaDetectionSummaryEvent"; meta_content:!"%sagan%",An Azure service principal received new privileges,An endpoint received new privileges,A process attempted to modify the TrustedInstaller service ImagePath,A process has escalated privileges, this could be as a result of an adversary's attempt to bypass access controls or as part of legitimate system administration,A user executed a valid accounts DCE/RPC command targeting a DC for the first time; parse_src_ip:1; normalize; reference:url,https://www.reddit.com/r/crowdstrike/comments/rbbzwi/pattern_disposition_values_in_detect_api/; classtype:trojan-activity; sid:5016656; rev:3; metadata:created_at 2025_06_25, updated_at 2026_03_26;)

Field Validations

Loading…

Comments (0)

Loading comments...