Tampering with Internet Explorer Protected Mode configuration
When an add-on is running inside Protected Mode attempts to launch a broker process (or any other program), the ElevationPolicy Registry key is checked to determine how the process should be launched. Internet Explorer will run a broker process with higher rights that can use the current user's permissions to take actions that would otherwise be prohibited when rendering content inside the Protected Mode sandbox. https://blogs.msdn.microsoft.com/ieinternals/2009/11/30/understanding-the-protected-mode-elevation-dialog/.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
When an add-on is running inside Protected Mode attempts to launch a broker process, this key is checked to determine how the process should be launched. Attackers may change this value to make the process launch with higher privileges.
Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
- Tampering with Internet Explorer Protected Mode default configuration Medium (parent: Informational)
- Tampering with Internet Explorer Protected Mode specific app configuration Informational