UAC Bypass Using WOW64 Logger DLL Hijack
Description
Detects the pattern of UAC Bypass using a WoW64 logger DLL hijack (UACMe 30)
Query · sigma
selection: SourceImage|contains: :\Windows\SysWOW64\ GrantedAccess: '0x1fffff' CallTrace|startswith: UNKNOWN(0000000000000000)|UNKNOWN(0000000000000000)| condition: selection
Known false positives
- Unknown