UAC Bypass Using MSConfig Token Modification - Process
Description
Detects the pattern of UAC Bypass using a msconfig GUI hack (UACMe 55)
Query · sigma
selection: IntegrityLevel: - High - System - S-1-16-16384 - S-1-16-12288 ParentImage|endswith: \AppData\Local\Temp\pkgmgr.exe CommandLine: '"C:\Windows\system32\msconfig.exe" -5' condition: selection
Known false positives
- Unknown