Detecting common Windows privilege escalation techniques with Wazuh
Privilege escalation is the process by which an attacker gains permissions beyond those assigned to their current account. On Windows endpoints, threat actors who gain initial access as a standard user may exploit misconfigurations to obtain administrator or NT AUTHORITY\SYSTEM privileges. With elevated privileges, an attacker can disable security controls, access protected files, dump credentials, […]