Potential Privilege Escalation Keywords in Command Line
This rule detects the execution of processes where the command line contains keywords commonly associated with privilege escalation or gaining administrative privileges, such as 'getadmin' or 'privesc'. It monitors Windows Security Event ID 4688, which logs process creation.
Microsoft Sentinel (KQL)

