UAC Bypass Using Iscsicpl - ImageLoad
Description
Detects the "iscsicpl.exe" UAC bypass technique that leverages a DLL Search Order hijacking technique to load a custom DLL's from temp or a any user controlled location in the users %PATH%
Query · sigma
selection: Image: C:\Windows\SysWOW64\iscsicpl.exe ImageLoaded|endswith: \iscsiexe.dll filter: ImageLoaded|contains|all: - C:\Windows\ - iscsiexe.dll condition: selection and not filter
Known false positives
- Unknown