Analytics BIOC Informational

Creation or modification of the default command executed when opening an application

Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002)
Attacker's goals:

Gain higher privileges by bypassing the User Account Control (UAC).

Investigative actions:

Check the registry data modified for a potentially malicious command line. Look for processes running matching the command line for malicious activity.

Test period:
N/A (single event)
Deduplication:
1 Day
4 variations:
  • Creation or modification of the default command executed when opening the Microsoft optional features settings (Fodhelper.exe) Medium (parent: Informational)
  • Creation or modification of the default command executed when opening an MMC application Medium (parent: Informational)
  • Creation or modification of the default command executed when opening Windows backup and restore (sdclt.exe) Medium (parent: Informational)
  • Creation or modification of the default command executed when opening Windows Store settings (Wsreset.exe) Medium (parent: Informational)