Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0004 ✕ technique: T1548 ✕
Download CSV Show ATT&CK heatmapCreation or modification of the default command executed when opening an application Informational 4 variations
Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Privilege Escalation (TA0004)ATT&CK techniques: Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Gain higher privileges by bypassing the User Account Control (UAC).Investigative actions: Check the registry data modified for a potentially malicious command line. Look for processes running matching the command line for malicious activity.Variations
Creation or modification of the default command executed when opening the Microsoft optional features settings (Fodhelper.exe)
Medium overridden
Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC. overridden
Creation or modification of the default command executed when opening an MMC application
Medium overridden
Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC. overridden
Creation or modification of the default command executed when opening Windows backup and restore (sdclt.exe)
Medium overridden
Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC. overridden
Creation or modification of the default command executed when opening Windows Store settings (Wsreset.exe)
Medium overridden
Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC. overridden