UAC Bypass Using NTFS Reparse Point - Process
Description
Detects the pattern of UAC Bypass using NTFS reparse point and wusa.exe DLL hijacking (UACMe 36)
Query · sigma
selection1:
CommandLine|startswith: '"C:\Windows\system32\wusa.exe" /quiet C:\Users\'
CommandLine|endswith: \AppData\Local\Temp\update.msu
IntegrityLevel:
- High
- System
- S-1-16-16384
- S-1-16-12288
selection2:
ParentCommandLine: '"C:\Windows\system32\dism.exe" /online /quiet /norestart /add-package
/packagepath:"C:\Windows\system32\pe386" /ignorecheck'
IntegrityLevel:
- High
- System
CommandLine|contains|all:
- C:\Users\
- \AppData\Local\Temp\
- \dismhost.exe {
Image|endswith: \DismHost.exe
condition: 1 of selection*
Known false positives
- Unknown