Technique T1068
Exploitation for Privilege Escalation
Detection & mitigation
Monitor for suspicious child processes spawned by ExifTool, especially shell interpreters (cmd.exe, /bin/sh) with arguments containing command separators. Apply vendor patch when available and restrict execution privileges.