Auditing Windows Uac And Integrity Boundaries

Audit elevation and integrity boundaries on Windows, where a medium-integrity process reaches a high- integrity context without a genuine consent prompt, through an auto-elevating binary that loads an attacker-influenced input, a writable resource an elevated process consumes, an over-broad elevation policy, or an integrity level that does not gate the operation it should. Use when reviewing how a host distinguishes elevated from non-elevated code and whether a non-administrator can cross that line without real consent. Covers auto-elevation abuse, elevated processes consuming writable inputs, permissive elevation policy, and integrity levels that fail to gate an operation. The medium-integrity influence over what an elevated process consumes is the source, the auto-elevating or elevated operation is the sink, and reaching a high- integrity context without genuine consent is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-windows-uac-and-integrity-boundaries commit 06d193798c

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-windows-uac-and-integrity-boundaries