Analytics BIOC
Informational
✕
Creation or modification of the default command executed when opening an application
Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002)
Attacker's goals:
Gain higher privileges by bypassing the User Account Control (UAC).
Investigative actions:
Check the registry data modified for a potentially malicious command line. Look for processes running matching the command line for malicious activity.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
4 variations:
- Creation or modification of the default command executed when opening the Microsoft optional features settings (Fodhelper.exe) Medium (parent: Informational)
- Creation or modification of the default command executed when opening an MMC application Medium (parent: Informational)
- Creation or modification of the default command executed when opening Windows backup and restore (sdclt.exe) Medium (parent: Informational)
- Creation or modification of the default command executed when opening Windows Store settings (Wsreset.exe) Medium (parent: Informational)