Windows SymbolicLink-Testing-Tools Utility Execution — Detection Rule
Detects the execution of tools from the `symboliclink-testing-tools` toolkit. This toolkit is often used for exploiting Windows symbolic link, junction, and oplock vulnerabilities to achieve local privilege escalation from a standard user to SYSTEM. Symbolic link attacks against Windows exploit a class of logical vulnerability where a SYSTEM or administrator-level process performs a file operation on a path that a low-privileged attacker can redirect using a combination of NTFS junctions, object manager symbolic links, and opportunistic locks (oplocks). By chaining these primitives a standard user can redirect a privileged file write, delete, or read to an arbitrary path, effectively turning a narrow file operation vulnerability into arbitrary write or code execution as SYSTEM.