UAC Bypass via ICMLuaUtil
Description
Detects the pattern of UAC Bypass using ICMLuaUtil Elevated COM interface
Query · sigma
selection:
ParentImage|endswith: \dllhost.exe
ParentCommandLine|contains:
- /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}
- /Processid:{D2E7041B-2927-42FB-8E9F-7CE93B6DC937}
filter:
- Image|endswith: \WerFault.exe
- OriginalFileName: WerFault.exe
condition: selection and not filter
Known false positives
- Unknown