UAC Bypass Using .NET Code Profiler on MMC
Description
Detects the pattern of UAC Bypass using .NET Code Profiler and mmc.exe DLL hijacking (UACMe 39)
Query · sigma
selection: TargetFilename|startswith: C:\Users\ TargetFilename|endswith: \AppData\Local\Temp\pe386.dll condition: selection
Known false positives
- Unknown