RunAs /savecred Abuse for Privilege Escalation (T1134.001)

Detects the execution of the Windows runas command using the /savecred flag. This flag instructs Windows to save the supplied credentials locally, which can be abused by unauthorized users to elevate privileges or execute processes in the context of a saved account without providing a password again.