Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0388 — Detection Strategy for T1548.002 – Bypass User Account Control (UAC)
DET0388

Detection Strategy for T1548.002 – Bypass User Account Control (UAC)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1094 Analytic 1094
Windows

Detects a multi-event behavior chain involving UAC bypass attempts via known auto-elevated binaries (e.g., eventvwr.exe, sdclt.exe), unauthorized Registry changes to UAC-related keys, and anomalous process execution with elevated privileges but lacking standard parent-child lineage. Suspicious patterns include invocation of auto-elevated COM objects or manipulation of isolatedCommand Registry entries without consent prompts.

WinEventLog:Security EventCode=4688 WinEventLog:Security EventCode=4672 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=7
[TimeWindow] Correlate registry tampering and elevation within a tunable time window (e.g., 30 seconds) to reduce noise from benign admin activity.
[ElevatedProcessNameList] Tunable list of suspicious elevated binaries (e.g., sdclt.exe, eventvwr.exe, computerdefaults.exe) known to support UAC bypass.
[ParentProcessAnomalyThreshold] Define logic for parent-child mismatch (e.g., non-elevated process spawning auto-elevated one) to flag uncommon elevation paths.

Detected Techniques

1

Details

MITRE ID
DET0388
STIX ID
x-mitre-detection-strategy--d6619253-10cd-4b90-84b5-364c418d2484
Analytics
1
Techniques Detected
1
By Tactic
Privilege Escalation
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.