Detecting T1548 Abuse Elevation Control Mechanism

mukul975/detecting-t1548-abuse-elevation-control-mechanism · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-child process relationships.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. Implementing Siem Correlation Rules For Apt · mukul975 bundle
    Detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts using Splunk SPL and Sigma rule format.
    24.6k
    repo stars
  2. Hunting For Lolbins Execution In Endpoint Logs · mukul975 bundle
    Hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs for suspicious execution patterns of legitimate Windows system binaries used for malicious purposes.
    24.6k
    repo stars
  3. Detecting Evasion Techniques In Endpoint Logs · mukul975 bundle
    Detects defense evasion techniques in endpoint logs, including log tampering, timestomping, process injection, and security tool disabling, using Sysmon, EDR telemetry, and SIEM queries.
    24.6k
    repo stars
  4. Detecting Lateral Movement With Splunk · mukul975 bundle
    Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.
    24.6k
    repo stars
  5. Detecting Credential Dumping Techniques · mukul975 bundle
    Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules.
    24.6k
    repo stars
  6. Detecting Golden Ticket Attacks In Kerberos Logs · mukul975 bundle
    Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.
    24.6k
    repo stars

Frequently asked questions

How do I install the Detecting T1548 Abuse Elevation Control Mechanism skill?

Run npx skillmds add mukul975/detecting-t1548-abuse-elevation-control-mechanism in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the Detecting T1548 Abuse Elevation Control Mechanism skill do?

Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-child process relationships. It is listed under Security, Coding & Dev Tools, Vulnerability Scanning on SkillMD.

Is Detecting T1548 Abuse Elevation Control Mechanism safe to use?

SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. Capability flags: executes scripts, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with Detecting T1548 Abuse Elevation Control Mechanism?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is Detecting T1548 Abuse Elevation Control Mechanism free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published Detecting T1548 Abuse Elevation Control Mechanism?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.