WCU / Cybersecurity
~/CSC 471/Class 08/KP 11
Class 08 · KP 11 / 20

Privilege Escalation, Defense Evasion, Discovery

  • Privilege Escalation: UAC bypass, token manipulation, exploit of a vulnerable driver; watch for elevation of the sample's integrity level.
  • Defense Evasion: disabling Defender (Set-MpPreference -DisableRealtimeMonitoring), clearing logs (wevtutil cl), deleting itself, process hollowing.
  • Discovery: whoami, systeminfo, ipconfig, net view, querying registry for installed AV.
Key Takeaway

Evasion actions (disabling AV, wiping logs) are themselves strong high-confidence indicators.