Right escalation via services or scheduled tasks in Windows
ID: d10c2878-6d97-5d62-b681-8ca6998518f3
STIX ID: report--d10c2878-6d97-5d62-b681-8ca6998518f3
Feed Name: SensePost Blog
This document describes a Windows privilege-escalation tactic that abuses overly privileged scheduled tasks and services to run attacker-controlled code, noting approaches such as replacing the targeted executable or injecting into the task’s process. It also references a potential Windows File Protection bypass and mentions supporting media (screenshots/video) to illustrate the technique.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
