You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
desc = "Detects executables which may attempt to exploit James Forshaw's Issue 1550, which allows for Local Elevation of Privilege. Specifically, this rule looks at the original vulnerability and will also catch using this vulnerability to create a false KnownDLLs directory in order to achieve arbitrary DLL injection into services.exe, which runs as the highest level of PPL. This can be used to open handles to other processes at the same PPL level or lower, which could allow for the disablement of many EDR products."