UAC Bypass Using IDiagnostic Profile - File
Description
Detects the creation of a file by "dllhost.exe" in System32 directory part of "IDiagnosticProfileUAC" UAC bypass technique
Query · sigma
selection: Image|endswith: \DllHost.exe TargetFilename|startswith: C:\Windows\System32\ TargetFilename|endswith: .dll condition: selection
Known false positives
- Unknown