logo

Right escalation via services or scheduled tasks in Windows

ID: d10c2878-6d97-5d62-b681-8ca6998518f3

STIX ID: report--d10c2878-6d97-5d62-b681-8ca6998518f3

Feed Name: SensePost Blog

Date Published: 2007-06-06

Date Updated: 2026-04-29

...
...

This document describes a Windows privilege-escalation tactic that abuses overly privileged scheduled tasks and services to run attacker-controlled code, noting approaches such as replacing the targeted executable or injecting into the task’s process. It also references a potential Windows File Protection bypass and mentions supporting media (screenshots/video) to illustrate the technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.