UAC Bypass Using NTFS Reparse Point - File
Description
Detects the pattern of UAC Bypass using NTFS reparse point and wusa.exe DLL hijacking (UACMe 36)
Query · sigma
selection: TargetFilename|startswith: C:\Users\ TargetFilename|endswith: \AppData\Local\Temp\api-ms-win-core-kernel32-legacy-l1.DLL condition: selection
Known false positives
- Unknown