LogoClawIndex
CasesSkillsAbout
LogoClawIndex

detecting-t1548-abuse-elevation-control-mechanism - Detecting T1548 Abuse Elevation Control Mechanism

Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation using system logs.

Tags

Updated: 2026-09-15

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Monitor UAC registry modifications
  • Detect auto-elevating process abuse
  • Track process integrity level changes
  • Hunt for elevated process spawning
  • Monitor Linux elevation abuse
  • Correlate privilege escalation events

Inputs

  • Sysmon Event ID 1 logs
  • Windows Security Event ID 4688 logs
  • UAC registry auditing data
  • Sysmon Event ID 12 and 13 logs
  • EDR elevation monitoring data

Outputs

  • Threat hunting report
  • UAC bypass detection alerts

Requirements

  • Sysmon with command-line logging
  • Windows Event 4688 with process tracking
  • Registry auditing for UAC keys
  • EDR elevation monitoring capabilities

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
threat-hunting
uac-bypass
privilege-escalation
mitre-t1548
elevation-control
windows-security
Monitor UAC registry modifications
Detect auto-elevating process abuse
Track process integrity level changes
Hunt for elevated process spawning
Sysmon Event ID 1 logs
Windows Security Event ID 4688 logs
UAC registry auditing data
Threat hunting report
UAC bypass detection alerts