RoguePlanet and GreatXML: Detecting Local Privilege Escalation and BitLocker Security Boundary Abuse
ID: 402e8634-1377-50fa-a206-a6c15b2beefa
STIX ID: report--402e8634-1377-50fa-a206-a6c15b2beefa
Feed Name: LevelBlue SpiderLabs Blog
This report analyzes two proof-of-concept Windows abuses from the Nightmare‑Eclipse cluster: RoguePlanet, which chains Defender processing, NTFS reparse points, opportunistic locks, VSS and Windows Error Reporting to escalate a standard user to SYSTEM without kernel or memory exploits; and GreatXML, which places a malicious unattend.xml on the recovery partition to enable WinRE-based access to BitLocker volumes after a Shift+Restart. The report provides a seven-stage technical breakdown for RoguePlanet, a three-stage plant/arm/trigger model for GreatXML, detailed behavioral detection guidance, and a set of deterministic IoCs (ADS artifacts, anomalous %TEMP% System32 dirs, recovery-partition unattend.xml, etc.).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
