INTEL_REPORT
Google Project Zero · published 1/25/2026, 11:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Bypassing Windows Administrator Protection A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Control (UAC) with a more robust and importantly, securable system to allow a local user to access administrator privileges only when necessary. This blog post will give a brief overview of the new feature, how it works and how it’s different from UAC. I’ll then describe some of the…
https://projectzero.google/2026/26/windows-administrator-protection.html
sha256:24a1bd79140ecceca8b35b7f7850b59f51cfe1f7e09c69a18599560c97e97f9a
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.