UAC Bypass via Sdclt
Description
Detects the pattern of UAC Bypass using registry key manipulation of sdclt.exe (e.g. UACMe 53)
Query · sigma
selection1:
TargetObject|endswith: Software\Classes\exefile\shell\runas\command\isolatedCommand
selection2:
TargetObject|endswith: Software\Classes\Folder\shell\open\command\SymbolicLinkValue
Details|re: -1[0-9]{3}\\Software\\Classes\\
condition: 1 of selection*
Known false positives
- Unknown