Mandiant, Inc.
Exploit of privilege detection framework

Last updated:

Abstract:

A non-transitory storage medium having stored thereon logic, the logic being executable by one or more processors to perform operations including comparing a current privilege of a first process with an initial privilege of the first process recorded in a privilege list, and responsive to determining a change exists between the current privilege of the first process and the initial privilege of the first process that is greater than a predetermined threshold, determining the first process is operating with the current privilege due to an exploit of privilege attack is shown.

Status:
Grant
Type:

Utility

Filling date:

29 Jun 2016

Issue date:

18 Feb 2020