Auditing Windows Token And Privilege Abuse

Audit privilege escalation through Windows access token and privilege abuse, where a process holds a sensitive privilege or can obtain a more privileged token, letting a lower-privileged foothold impersonate a privileged caller, load a driver, take ownership, back up protected files, or debug another process to reach a higher context. Use when a service or process runs with a named sensitive privilege enabled or can receive and impersonate tokens from privileged callers. Covers impersonation privileges, token theft and duplication, and the backup, restore, ownership, load-driver, and debug privileges. The privilege or the capturable privileged token is the source, the operation the privilege authorizes is the sink, and reaching a higher-privileged context from a lower one is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-windows-token-and-privilege-abuse commit 9c3248d4b0

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-windows-token-and-privilege-abuse