mitre_attack_T1548_002_windows_uac_bypass
Description
Net use commands for SMB/Windows admin shares
Query · yara_l
events:
(
$e1.metadata.event_type = "PROCESS_LAUNCH" and
re.regex($e1.principal.process.command_line, `reg\.exe add hkcu\\software\\classes\\mscfile\\shell\\open\\command /ve /d.* /f`) nocase
)
or
(
re.regex($e1.principal.process.command_line, `powershell.exe`) nocase and
re.regex($e1.target.registry.registry_key, `\\software\\classes\\mscfile\\shell\\open\\command`) nocase
)
condition:
$e1