PowerShell silent elevation via Start-Process -Verb RunAs relaunch
Detects instances where PowerShell attempts to execute an external process with elevated privileges using 'Start-Process -Verb RunAs' combined with hidden window flags. The rule specifically looks for evidence that the targeted executable was recently initiated or exists in the context of the PowerShell operation, potentially indicating a UAC bypass attempt or malicious elevation of privileges.
Microsoft Sentinel (KQL)

