Privilege Escalation, Defense Evasion, Discovery
- Privilege Escalation: UAC bypass, token manipulation, exploit of a vulnerable driver; watch for elevation of the sample's integrity level.
- Defense Evasion: disabling Defender (
Set-MpPreference -DisableRealtimeMonitoring), clearing logs (wevtutil cl), deleting itself, process hollowing. - Discovery:
whoami,systeminfo,ipconfig,net view, querying registry for installed AV.
Key Takeaway
Evasion actions (disabling AV, wiping logs) are themselves strong high-confidence indicators.