Mandiant, Inc.
Exploit of privilege detection framework
Last updated:
Abstract:
A non-transitory storage medium having stored thereon logic, the logic being executable by one or more processors to perform operations including comparing a current privilege of a first process with an initial privilege of the first process recorded in a privilege list, and responsive to determining a change exists between the current privilege of the first process and the initial privilege of the first process that is greater than a predetermined threshold, determining the first process is operating with the current privilege due to an exploit of privilege attack is shown.
Status:
Grant
Type:
Utility
Filling date:
29 Jun 2016
Issue date:
18 Feb 2020