UAC Bypass Using Disk Cleanup
Description
Detects the pattern of UAC Bypass using scheduled tasks and variable expansion of cleanmgr.exe (UACMe 34)
Query · sigma
selection: CommandLine|endswith: '"\system32\cleanmgr.exe /autoclean /d C:' ParentCommandLine: C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule IntegrityLevel: - High - System - S-1-16-16384 - S-1-16-12288 condition: selection
Known false positives
- Unknown