kevmap

TechniquesT1548 › T1548.002

T1548.002 Bypass User Account Control

privilege escalation — Windows · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
56
Sigma rules tagged attack.t1548.002
1
KEV CVEs mapped here
<p>Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action.</p><p>If the UAC protection level of a computer is set to anything but the highest level, certain Windows programs can elevate privileges or execute some elevated Component Object Model objects without prompting the user through the UAC notification box. An example of this is use of Rundll32 to load a specifically crafted DLL which loads an auto-elevated Component Object Model object and performs a file operation in a protected directory which would typically require elevated access. Malicious software may also be injected into a trusted process to gain elevated privileges without prompting a user.</p><p>Many methods have been discovered to bypass UAC. The Github readme page for UACME contains an extensive list of methods that have been discovered and implemented, but may not be a comprehensive list of bypasses. Additional bypass methods are regularly discovered and some used in the wild, such as:</p>
    <li><code>eventvwr.exe</code> can auto-elevate and execute a specified binary or script.</li>
<p>Another bypass is possible through some lateral movement techniques if credentials for an account with administrator privileges are known, since UAC is a single system security mechanism, and the privilege or integrity of a process running on one system will be unknown on remote systems and default to high integrity.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2021-31207Microsoft Exchange Server exploitation technique Mapped2021-11-03

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1548.002

Author: Christian Burkard (Nextron Systems) · 2021-08-23 (modified 2024-12-01) · logsource: product=windows category=process_creation · 0058b9e5-bcd7-40d4-9205-95ca5a16d7b2
Detects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)
Techniques: T1548.002
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-06-17 · logsource: product=windows category=image_load · 0cbe38c0-270c-41d9-ab79-6e5a9a669290
Detects DLLs loading from a spoofed Windows directory path with an extra space (e.g "C:\Windows \System32") which can bypass Windows trusted path verification. This technique tricks Windows into treating the path as trusted, allowing malicious DLLs to load with high integrity privileges bypassing UAC.
Techniques: T1574.007T1548.002
Author: frack113 · 2024-05-10 · logsource: product=windows category=registry_set · 0d7ceeef-3539-4392-8953-3dc664912714
Detects when an attacker tries to change User Account Control (UAC) elevation request destination via the "PromptOnSecureDesktop" value. The "PromptOnSecureDesktop" setting specifically determines whether UAC prompts are displayed on the secure desktop. The secure desktop is a separate desktop environment that's isolated from other processes running on the system. It's designed to prevent malicious software from intercepting or tampering with UAC prompts. When "PromptOnSecureDesktop" is set to 0, UAC prompts are displayed on the user's current desktop instead of the secure desktop. This reduces the level of security because it potentially exposes the prompts to manipulation by malicious software.
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2022-01-13) · logsource: product=windows category=registry_event · 152f3630-77c1-4284-bcc0-4cc68ab2f6e7
Detects the shell open key manipulation (exefile and ms-settings) used for persistence and the pattern of UAC Bypass using fodhelper.exe, computerdefaults.exe, slui.exe via registry keys (e.g. UACMe 33 or 62)
Techniques: T1548.002T1546.001
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2022-10-09) · logsource: product=windows category=file_event · 155dbf56-e0a4-4dd0-8905-8a98705045e8
Detects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-23 (modified 2024-12-01) · logsource: product=windows category=process_creation · 1ca6bd18-0ba0-44ca-851c-92ed89a61085
Detects the pattern of UAC Bypass using consent.exe and comctl32.dll (UACMe 22)
Techniques: T1548.002
Author: Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community · 2020-10-13 (modified 2022-10-20) · logsource: product=windows category=process_creation · 1e53dd56-8d83-4eb4-a43e-b790a05510aa
Detects Windows Installer service (msiexec.exe) spawning "cmd" or "powershell"
Techniques: T1548.002
Author: Ecco · 2019-08-30 (modified 2023-02-21) · logsource: product=windows category=process_creation · 3268b746-88d8-4cd3-bffc-30077d02c787
Detects some Empire PowerShell UAC bypass methods
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2024-12-01) · logsource: product=windows category=process_creation · 39ed3c80-e6a1-431b-9df3-911ac53d08a7
Detects the pattern of UAC Bypass using NTFS reparse point and wusa.exe DLL hijacking (UACMe 36)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-31 (modified 2024-12-01) · logsource: product=windows category=process_creation · 3c05e90d-7eba-4324-9972-5d7f711a60a8
Detects tools such as UACMe used to bypass UAC with computerdefaults.exe (UACMe 59)
Techniques: T1548.002
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) · 2020-05-02 (modified 2024-12-01) · logsource: product=windows category=process_creation · 40f9af16-589d-4984-b78d-8c2aec023197
A General detection for sdclt being spawned as an elevated process. This could be an indicator of sdclt being used for bypass UAC techniques.
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2022-10-09) · logsource: product=windows category=file_event · 41bb431f-56d8-4691-bb56-ed34e390906f
Detects the pattern of UAC Bypass using a msconfig GUI hack (UACMe 55)
Techniques: T1548.002
Author: frack113 · 2022-01-05 (modified 2023-08-17) · logsource: product=windows category=registry_set · 46dd5308-4572-4d12-aa43-8938f0184d4f
Bypasses User Account Control using a fileless method
Techniques: T1548.002
UAC Disabled mediumstable
Author: frack113 · 2022-01-05 (modified 2024-05-10) · logsource: product=windows category=registry_set · 48437c39-9e5f-47fb-af95-3d663c3f2919
Detects when an attacker tries to disable User Account Control (UAC) by setting the registry value "EnableLUA" to 0.
Techniques: T1548.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-07-03 · logsource: product=windows category=file_event · 48ea844d-19b1-4642-944e-fe39c2cc1fec
Detects the creation of a file by "dllhost.exe" in System32 directory part of "IDiagnosticProfileUAC" UAC bypass technique
Techniques: T1548.002
Author: Florian Roth (Nextron Systems), Elastic (idea) · 2022-09-13 (modified 2022-09-27) · logsource: product=windows category=process_creation · 49f2f17b-b4c8-4172-a68b-d5bf95d05130
Detects the pattern of UAC Bypass using ICMLuaUtil Elevated COM interface
Techniques: T1548.002
Author: Florian Roth (Nextron Systems) · 2021-08-27 (modified 2025-06-17) · logsource: product=windows category=process_creation · 4ac47ed3-44c2-4b1f-9d51-bf46e8914126
Detects indicators of a UAC bypass method by mocking directories
Techniques: T1548.002
Author: Nik Seetharaman, Christian Burkard (Nextron Systems) · 2019-07-31 (modified 2024-12-01) · logsource: product=windows category=process_creation · 4b60e6f2-bf39-47b4-b4ea-398e33cfe253
Detects UAC Bypass Attempt Using Microsoft Connection Manager Profile Installer Autoelevate-capable COM Objects (e.g. UACMe ID of 41, 43, 58 or 65)
Techniques: T1548.002T1218.003
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-07-03 (modified 2024-12-01) · logsource: product=windows category=process_creation · 4cbef972-f347-4170-b62a-8253f6168e6d
Detects the "IDiagnosticProfileUAC" UAC bypass technique
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-23 (modified 2022-10-09) · logsource: product=windows category=process_access · 4f6c43e2-f989-4ea5-bcd8-843b49a0317c
Detects the pattern of UAC Bypass using a WoW64 logger DLL hijack (UACMe 30)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-23 (modified 2024-12-01) · logsource: product=windows category=process_creation · 503d581c-7df0-4bbe-b9be-5840c0ecc1fc
Detects an UAC bypass that uses changepk.exe and slui.exe (UACMe 61)
Techniques: T1548.002
Author: Florian Roth (Nextron Systems) · 2022-02-23 (modified 2022-04-21) · logsource: product=windows category=process_creation · 534f2ef7-e8a2-4433-816d-c91bccde289b
Detects suspicious starts of explorer.exe that use the /NOUACCHECK flag that allows to run all sub processes of that newly started explorer.exe without any UAC checks
Techniques: T1548.002
Author: Omer Yampel, Christian Burkard (Nextron Systems) · 2017-03-17 (modified 2023-08-17) · logsource: product=windows category=registry_set · 5b872a46-3b90-45c1-8419-f675db8053aa
Detects the pattern of UAC Bypass using registry key manipulation of sdclt.exe (e.g. UACMe 53)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-23 (modified 2023-08-17) · logsource: product=windows category=registry_set · 5f9db380-ea57-4d1e-beab-8a2d33397e93
Detects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-23 (modified 2022-10-09) · logsource: product=windows category=file_event · 62ed5b55-f991-406a-85d9-e8e8fdf18789
Detects the pattern of UAC Bypass using consent.exe and comctl32.dll (UACMe 22)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2023-08-17) · logsource: product=windows category=registry_set · 6597be7b-ac61-4ac8-bef4-d3ec88174853
Detects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-23 (modified 2022-10-09) · logsource: product=windows category=file_event · 68578b43-65df-4f81-9a9b-92f32711a951
Detects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)
Techniques: T1548.002
Author: oscd.community, Dmitry Uchakin · 2020-10-07 (modified 2021-11-27) · logsource: product=windows category=registry_event · 6ea3bf32-9680-422d-9f50-e90716b12a66
Unfixed method for UAC bypass from Windows 10. WSReset.exe file associated with the Windows Store. It will run a binary file contained in a low-privilege registry.
Techniques: T1548.002
Author: frack113, Nextron Systems · 2022-01-06 (modified 2024-01-30) · logsource: product=windows category=registry_set · 724ea201-6514-4f38-9739-e5973c34f49a
Detects the setting of the environement variable "windir" to a non default value. Attackers often abuse this variable in order to trigger a UAC bypass via the "SilentCleanup" task. The SilentCleanup task located in %windir%\system32\cleanmgr.exe is an auto-elevated task that can be abused to elevate any file with administrator privileges without prompting UAC.
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2024-12-01) · logsource: product=windows category=process_creation · 7a01183d-71a2-46ad-ad5c-acd989ac1793
Detects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)
Techniques: T1548.002
Author: Florian Roth (Nextron Systems) · 2017-03-19 (modified 2023-09-28) · logsource: product=windows category=registry_set · 7c81fec3-1c1d-43b0-996a-46753041b1b6
Detects UAC bypass method using Windows event viewer
Techniques: T1548.002
Author: Michael Haag · 2024-09-03 · logsource: product=windows category=process_creation · 7e8f2d3b-9c1a-4f67-b9e8-8d9006e0e51f
Detects the use of DISM to enable the PowerShell Web Access feature, which could be used for remote access and potential abuse
Techniques: T1548.002
Author: E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community · 2019-10-24 (modified 2021-11-27) · logsource: product=windows category=process_creation · 7f741dcf-fc22-4759-87b4-9ae8376676a2
Identifies use of Fodhelper.exe to bypass User Account Control. Adversaries use this technique to execute privileged processes.
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2022-10-09) · logsource: product=windows category=file_event · 7fff6773-2baa-46de-a24a-b6eec1aba2d1
Detects the pattern of UAC Bypass using NTFS reparse point and wusa.exe DLL hijacking (UACMe 36)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2024-12-01) · logsource: product=windows category=process_creation · 80fc36aa-945e-4181-89f2-2f907ab6775d
Detects the pattern of UAC Bypass using IEInstal.exe (UACMe 64)
Techniques: T1548.002
Author: Swachchhanda Shrawan Poudel · 2023-12-04 · logsource: product=windows category=ps_script · 851fd622-b675-4d26-b803-14bc7baa517a
Detects scriptblock text keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2024-12-01) · logsource: product=windows category=process_creation · 853e74f9-9392-4935-ad3b-2e8c040dae86
Detects the pattern of UAC Bypass using DismHost DLL hijacking (UACMe 63)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-23 (modified 2024-12-01) · logsource: product=windows category=process_creation · 89a9a0e0-f61a-42e5-8957-b1479565a658
Detects the pattern of UAC Bypass via WSReset usable by default sysmon-config
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2022-10-09) · logsource: product=windows category=file_event · 93a19907-d4f9-4deb-9f91-aac4692776a6
Detects the pattern of UAC Bypass using .NET Code Profiler and mmc.exe DLL hijacking (UACMe 39)
Techniques: T1548.002
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2026-01-24 · logsource: product=windows category=registry_set · 9e8894c0-0ae0-11ef-9d85-1f2942bec57c
Detects modifications to shell open registry keys that point to suspicious locations typically used by malware for persistence. Generally, modifications to the `*\shell\open\command` registry key can indicate an attempt to change the default action for opening files, and various UAC bypass or persistence techniques involve modifying these keys to execute malicious scripts or binaries.
Techniques: T1548.002T1546.001
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-07-17 (modified 2022-07-25) · logsource: product=windows category=image_load · 9ed5959a-c43c-4c59-84e3-d28628429456
Detects the "iscsicpl.exe" UAC bypass technique that leverages a DLL Search Order hijacking technique to load a custom DLL's from temp or a any user controlled location in the users %PATH%
Techniques: T1548.002
Author: oscd.community, Dmitry Uchakin · 2020-10-06 (modified 2022-12-25) · logsource: product=windows category=image_load · a5ea83a7-05a5-44c1-be2e-addccbbd8c03
Attempts to load dismcore.dll after dropping it
Techniques: T1548.002T1574.001
Author: Christian Burkard (Nextron Systems) · 2021-08-23 (modified 2024-12-01) · logsource: product=windows category=process_creation · a743ceba-c771-4d75-97eb-8a90f7f4844c
Detects the pattern of UAC Bypass using pkgmgr.exe and dism.exe (UACMe 23)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2024-12-01) · logsource: product=windows category=process_creation · ad92e3f9-7eb6-460e-96b1-582b0ccbb980
Detects the pattern of UAC Bypass using a msconfig GUI hack (UACMe 55)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2024-12-01) · logsource: product=windows category=process_creation · b697e69c-746f-4a86-9f59-7bfff8eab881
Detects the pattern of UAC Bypass using scheduled tasks and variable expansion of cleanmgr.exe (UACMe 34)
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2022-10-09) · logsource: product=windows category=file_event · bdd8157d-8e85-4397-bb82-f06cc9c71dbb
Detects the pattern of UAC Bypass using IEInstal.exe (UACMe 64)
Techniques: T1548.002
Author: Florian Roth (Nextron Systems) · 2017-03-19 (modified 2023-09-28) · logsource: product=windows category=process_creation · be344333-921d-4c4d-8bb8-e584cf584780
Detects uncommon or suspicious child processes of "eventvwr.exe" which might indicate a UAC bypass attempt
Techniques: T1548.002
Author: frack113, Nasreddine Bencherchali (Nextron Systems) · 2024-05-10 · logsource: product=windows category=registry_set · c5f6a85d-b647-40f7-bbad-c10b66bab038
Detects when an attacker tries to disable User Account Control (UAC) notification by tampering with the "UACDisableNotify" value. UAC is a critical security feature in Windows that prevents unauthorized changes to the operating system. It prompts the user for permission or an administrator password before allowing actions that could affect the system's operation or change settings that affect other users. When "UACDisableNotify" is set to 1, UAC prompts are suppressed.
Techniques: T1548.002
Author: Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community · 2020-10-13 (modified 2024-12-01) · logsource: product=windows category=process_creation · cd951fdc-4b2f-47f5-ba99-a33bf61e3770
Detects Windows Installer service (msiexec.exe) trying to install MSI packages with SYSTEM privilege
Techniques: T1548.002
Author: Christian Burkard (Nextron Systems), Florian Roth (Nextron Systems) · 2021-08-30 (modified 2024-11-23) · logsource: product=windows category=process_creation · d38d2fa4-98e6-4a24-aff1-410b0c9ad177
Detects the execution of UACMe, a tool used for UAC bypasses, via default PE metadata
Techniques: T1548.002
Author: Swachchhanda Shrawan Poudel · 2023-12-04 · logsource: product=windows category=process_creation · d557dc06-62e8-4468-a8e8-7984124908ce
Detects commandline keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.
Author: E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Florian Roth · 2019-10-24 (modified 2022-05-13) · logsource: product=windows category=process_creation · d797268e-28a9-49a7-b9a8-2f5039011c5c
Detects use of WSReset.exe to bypass User Account Control (UAC). Adversaries use this technique to execute privileged processes.
Techniques: T1548.002
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) · 2020-05-02 (modified 2021-11-27) · logsource: product=windows category=process_creation · da2738f2-fadb-4394-afa7-0a0674885afa
A General detection for sdclt spawning new processes. This could be an indicator of sdclt being used for bypass UAC techniques.
Techniques: T1548.002
Author: frack113, Swachchhanda Shrawan Poudel (Nextron Systems) · 2021-12-20 (modified 2026-01-24) · logsource: product=windows category=process_creation · dd3ee8cc-f751-41c9-ba53-5a32ed47e563
Detects registry modifications to the 'ms-settings' protocol handler, which is frequently targeted for UAC bypass or persistence. Attackers can modify this registry to execute malicious code with elevated privileges by hijacking the command execution path.
Author: E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community · 2019-10-24 (modified 2022-08-30) · logsource: product=windows category=process_creation · e66779cc-383e-4224-a3a4-267eeb585c40
Detect commandline usage of Microsoft Connection Manager Profile Installer (cmstp.exe) to install specially formatted local .INF files
Techniques: T1548.002T1218.003
Author: oscd.community, Dmitry Uchakin · 2020-10-07 (modified 2023-11-30) · logsource: product=windows category=process_access · fb3722e4-1a06-46b6-b772-253e2e7db933
Detects function calls from the EditionUpgradeManager COM interface. Which is an interface that is not used by standard executables.
Techniques: T1548.002

Rules tagged at the parent level (attack.t1548) 24

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Sittikorn S, Teoderick Contreras · 2022-01-20 (modified 2022-12-31) · logsource: product=linux category=file_event · 00eee2a5-fdb0-4746-a21d-e43fbdea5681
Detects the creation of doas.conf file in linux host platform.
Techniques: T1548
Author: Sittikorn S, Teoderick Contreras · 2022-01-20 · logsource: product=linux category=process_creation · 067d8238-7127-451c-a9ec-fa78045b618b
Detects the doas tool execution in linux host platform. This utility tool allow standard users to perform tasks as root, the same way sudo does.
Techniques: T1548
Author: Omkar Gudhate · 2020-09-27 (modified 2023-09-28) · logsource: product=windows category=registry_set · 07743f65-7ec9-404a-a519-913db7118a8d
Detects changes to 'HKCU\Software\Classes\Folder\shell\open\command\DelegateExecute'
Techniques: T1546T1548
Author: Corissa Koopmans, '@corissalea' · 2022-07-18 · logsource: product=azure service=auditlogs · 0922467f-db53-4348-b7bf-dee8d0d348c6
Monitor and alert on conditional access changes.
Techniques: T1548
Author: Florent Labouyrie · 2021-04-30 (modified 2022-10-09) · logsource: product=windows category=process_access · 174afcfa-6e40-4ae9-af64-496546389294
Detects when a process tries to access the memory of svchost to potentially dump credentials.
Techniques: T1548
Author: Corissa Koopmans, '@corissalea' · 2022-07-19 · logsource: product=azure service=auditlogs · 26e7c5e2-6545-481e-b7e6-050143459635
Monitor and alert on conditional access changes where non approved actor removed CA Policy.
Techniques: T1548T1556
Author: Milad Cheraghi · 2026-04-28 · logsource: product=linux category=process_creation · 33b3cfb1-574e-44b9-b527-fbf9303b9d7b
Detects attempts of an attacker to enable core dumps for set-user-ID (SUID) processes by modifying the system file /proc/sys/fs/suid_dumpable, typically by setting its value to 1 or 2. Enabling this feature allows memory dumps (core dumps) of SUID processes, which usually run with elevated privileges. These dumps may contain sensitive information such as passwords, cryptographic keys or other secrets. CVE-2025-5054: Information leak via core dumps from SUID binaries using apport. CVE-2025-4598: Information disclosure in systemd-coredump due to insecure handling of SUID process memory dumps.
Techniques: T1548T1003
CVE tags: CVE-2025-5054CVE-2025-4598
Author: Luc Génaux · 2026-01-24 · logsource: product=linux category=process_creation · 3a716279-c18c-4488-83be-f9ececbfb9fc
Detects the use of the 'setcap' utility to set the 'setgid' capability (cap_setgid) on a binary file. This capability allows a non privileged process to make arbitrary manipulations of group IDs (GIDs), including setting its current GID to a value that would otherwise be restricted (i.e. GID 0, the root group). This behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.
Techniques: T1548T1554
Author: Corissa Koopmans, '@corissalea' · 2022-07-19 (modified 2024-05-28) · logsource: product=azure service=auditlogs · 50a3c7aa-ec29-44a4-92c1-fce229eef6fc
Monitor and alert on conditional access changes. Is Initiated by (actor) approved to make changes? Review Modified Properties and compare "old" vs "new" value.
Techniques: T1548T1556
Author: Mark Morowczynski '@markmorow', Thomas Detzner '@tdetzner' · 2022-08-04 · logsource: product=azure service=auditlogs · 665e2d43-70dc-4ccc-9d27-026c9dd7ed9c
Monitor and alert on group membership removal of groups that have CA policy modification access
Techniques: T1548T1556
Author: Elastic, @SBousseaden · 2022-04-27 (modified 2024-08-13) · logsource: product=windows service=security · 749c9f5e-b353-4b90-a9c1-05243357ca4b
Detects a suspicious local successful logon event where the Logon Package is Kerberos, the remote address is set to localhost, and the target user SID is the built-in local Administrator account. This may indicate an attempt to leverage a Kerberos relay attack variant that can be used to elevate privilege locally from a domain joined limited user to local System privileges.
Techniques: T1548
Author: Bryan Lim · 2024-01-12 · logsource: product=gcp service=gcp.audit · 76737c19-66ee-4c07-b65a-a03301d1573d
Detects the deployment of workloads that are deployed by using the break-glass flag to override Binary Authorization controls.
Techniques: T1548
Author: Florian Roth (Nextron Systems) · 2021-05-27 (modified 2022-10-09) · logsource: product=windows category=process_creation · 883835a7-df45-43e4-bf1d-4268768afda4
Detects a regedit started with TrustedInstaller privileges or by ProcessHacker.exe
Techniques: T1548
Author: Austin Songer @austinsonger · 2021-07-24 (modified 2022-10-09) · logsource: product=aws service=cloudtrail · 905d389b-b853-46d0-9d3d-dea0d3a3cd49
Identifies the suspicious use of AssumeRole. Attackers could move laterally and escalate privileges.
Author: Mark Morowczynski '@markmorow', Thomas Detzner '@tdetzner' · 2022-08-04 · logsource: product=azure service=auditlogs · 91c95675-1f27-46d0-bead-d1ae96b97cd3
Monitor and alert on group membership additions of groups that have CA policy modification access
Techniques: T1548T1556
Author: NVISO · 2020-09-15 (modified 2022-12-25) · logsource: product=windows service=system · a0cb7110-edf0-47a4-9177-541a4083128a
Detects that a vulnerable Netlogon secure channel connection was allowed, which could be an indicator of CVE-2020-1472.
Techniques: T1548
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2026-07-23 · logsource: product=windows category=file_event · a7f3c891-2e4d-4b6a-9f8c-d5e2a1b04c73
Detects the creation of a registry hive file (UsrClass.dat or NTUSER.DAT) outside of the standard user profile path. These files generally contain various user-specific registry settings and are typically located in the user's profile directory. Staging these files outside of the standard path can be indicative of an attacker attempting to manipulate user registry settings for persistence, privilege escalation, or dump user registry hives for credential harvesting.
Techniques: T1548T1003
Author: Austin Songer @austinsonger · 2021-07-24 (modified 2022-10-09) · logsource: product=aws service=cloudtrail · b45ab1d2-712f-4f01-a751-df3826969807
Identifies the suspicious use of GetSessionToken. Tokens could be created and used by attackers to move laterally and escalate privileges.
Author: Semanur Guneysu @semanurtg, oscd.community · 2020-10-28 (modified 2022-11-11) · logsource: product=windows category=process_creation · d522eca2-2973-4391-a3e0-ef0374321dae
Detection of unusual child processes by different system processes
Techniques: T1548
Author: Roberto Rodriguez @Cyb3rWard0g, Tim Shelton · 2019-08-15 (modified 2022-09-18) · logsource: product=windows service=security · dae8171c-5ec6-4396-b210-8466585b53e9
Detects non-system users performing privileged operation os the SCM database
Techniques: T1548
Author: Tim Rauch, Elastic (idea) · 2022-09-27 · logsource: product=windows category=process_creation · e52cb31c-10ed-4aea-bcb7-593c9f4a315b
Detects attempts to bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in
Techniques: T1548
Author: Luc Génaux · 2026-01-24 · logsource: product=linux category=process_creation · ed447910-bc30-4575-a598-3a2e49516a7a
Detects the use of the 'setcap' utility to set the 'setuid' capability (cap_setuid) on a binary file. This capability allows a non privileged process to make arbitrary manipulations of user IDs (UIDs), including setting its current UID to a value that would otherwise be restricted (i.e. UID 0, the root user). This behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.
Techniques: T1548T1554
Author: Austin Songer · 2021-09-22 (modified 2022-12-18) · logsource: product=aws service=cloudtrail · f43f5d2f-3f2a-4cc8-b1af-81fde7dbaf0e
Identifies when suspicious SAML activity has occurred in AWS. An adversary could gain backdoor access via SAML.
Author: Pawel Mazur · 2021-11-28 (modified 2022-12-25) · logsource: product=linux service=auditd · fe10751f-1995-40a5-aaa2-c97ccb4123fe
Detects attempts to discover the files with setuid/setgid capability on them. That would allow adversary to escalate their privileges.
Techniques: T1083T1548