解析 eventvwr.exe 利用 mscfile 登錄檔劫持與 auto-elevate 機制繞過 UAC 的經典提權技術,包含攻擊原理、PowerShell PoC、Windows 11 現況測試,以及登錄檔監控、Sysmon 等偵測防禦方法。
Topic: #Privilege Escalation
A collection of 1 post about Privilege Escalation.
A collection of 1 post about Privilege Escalation.
解析 eventvwr.exe 利用 mscfile 登錄檔劫持與 auto-elevate 機制繞過 UAC 的經典提權技術,包含攻擊原理、PowerShell PoC、Windows 11 現況測試,以及登錄檔監控、Sysmon 等偵測防禦方法。