detecting-t1548-abuse-elevation-control-mechanism
mukul975/Anthropic-Cybersecurity-Skills
A comprehensive guide for threat hunting designed to detect various forms of privilege escalation abuse, including UAC bypass, setuid/setgid manipulation, and exploiting auto-elevating processes on Windows and Linux. It provides specific monitoring workflows, detection queries (Splunk, KQL, Sigma), and key indicators related to MITRE ATT&CK T1548.