> For the complete documentation index, see [llms.txt](https://breakpoint-journal.gitbook.io/breakpoint/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://breakpoint-journal.gitbook.io/breakpoint/windows/windows-privilege-escalation/installed-to-be-wild-privesc-paths-in-windows-apps/splunk-uf-universal-forwarder.md).

# Splunk (UF) Universal Forwarder

In the past, Splunk Universal Forwarder was a services installed on endpoints to forward logs to Splunk. Default Splunk configurations didn't have authentication and allowed anyone to deploy applications which could lead to code execution. It also defaulted to `SYSTEM$` and not a low privilege user. See [Splunk Hijacking](https://airman604.medium.com/splunk-universal-forwarder-hijacking-5899c3e0e6b2), and [SplunkWhisperer2](https://clement.notin.org/blog/2019/02/25/Splunk-Universal-Forwarder-Hijacking-2-SplunkWhisperer2/). (2018-2019)
