UAC Bypass Using Consent and Comctl32 - Process
Description
Detects the pattern of UAC Bypass using consent.exe and comctl32.dll (UACMe 22)
Query · sigma
selection: ParentImage|endswith: \consent.exe Image|endswith: \werfault.exe IntegrityLevel: - High - System - S-1-16-16384 - S-1-16-12288 condition: selection
Known false positives
- Unknown