Submit
detecting-t1548-abuse-elevation-control-mechanism Agent Skill Logo

detecting-t1548-abuse-elevation-control-mechanism

killvxk

通过监控注册表修改、进程提升标志和异常的父子进程关系,检测提升控制机制滥用,包括 UAC 绕过、sudo 利用和 setuid/setgid 操纵。

11
2
Created 2026-03-18
Updated 2026-03-18
自动化 API 搜索
SKILL.md
Files

Loading...

Loading...

Download Skill

Includes SKILL.md and all related files