UAC Bypass via Control Panel Execution Hijack


Description

Identifies attempts to bypass User Account Control (UAC) via hijacking the default handler of the Backup and Restore control panel. Attackers bypass UAC to stealthily execute code with elevated permissions.

Query · eql

sequence with maxspan=1m
  [registry where
   registry.hive == "HKEY_USERS" and
   registry.key : "S-1-5-21*_Classes\\Folder\\Shell\\Open\\Command*"]
  [process where event.action == "start" and process.pe.original_file_name : "sdclt.exe"]
  [process where event.action == "start" and
   process.Ext.token.integrity_level_name == "high" and
   process.parent.name : "control.exe" and process.parent.command_line : "*Microsoft.BackupAndRestoreCenter*"]
Raw source UAC Bypass via Control Panel Execution Hijack · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = """
Identifies attempts to bypass User Account Control (UAC) via hijacking the default handler of the Backup and Restore
control panel. Attackers bypass UAC to stealthily execute code with elevated permissions.
"""
id = "0545f127-b1ae-478a-a68a-84f477f765e2"
license = "Elastic License v2"
name = "UAC Bypass via Control Panel Execution Hijack"
os_list = ["windows"]
reference = ["https://github.com/hfiref0x/UACME"]
version = "1.0.33"

query = '''
sequence with maxspan=1m
  [registry where
   registry.hive == "HKEY_USERS" and
   registry.key : "S-1-5-21*_Classes\\Folder\\Shell\\Open\\Command*"]
  [process where event.action == "start" and process.pe.original_file_name : "sdclt.exe"]
  [process where event.action == "start" and
   process.Ext.token.integrity_level_name == "high" and
   process.parent.name : "control.exe" and process.parent.command_line : "*Microsoft.BackupAndRestoreCenter*"]
'''

min_endpoint_version = "7.15.0"
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 2

[[optional_actions]]
action = "rollback"
field = "process.entity_id"
state = 2

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1548"
name = "Abuse Elevation Control Mechanism"
reference = "https://attack.mitre.org/techniques/T1548/"
[[threat.technique.subtechnique]]
id = "T1548.002"
name = "Bypass User Account Control"
reference = "https://attack.mitre.org/techniques/T1548/002/"



[threat.tactic]
id = "TA0004"
name = "Privilege Escalation"
reference = "https://attack.mitre.org/tactics/TA0004/"

[internal]
min_endpoint_version = "7.15.0"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.