T1548.002Privilege EscalationAdvanced
UAC Bypass and Access Token Manipulation: Local Privilege Escalation
A comprehensive map of Windows UAC bypass (T1548.002) and access token manipulation (T1134) techniques: integrity levels, HKCU registry hijack families (fodhelper/eventvwr/sdclt/computerdefaults/SilentCleanup), token theft API chain, SeImpersonatePrivilege, and the Potato family (JuicyPotato/PrintSpoofer/RoguePotato/GodPotato). For each technique, the how-it-works → how-to-detect → how-to-prevent triad is provided.
35 min read
Exploit
Prevention
Detection