Analytics BIOC Informational

Tampering with Internet Explorer Protected Mode configuration

When an add-on is running inside Protected Mode attempts to launch a broker process (or any other program), the ElevationPolicy Registry key is checked to determine how the process should be launched. Internet Explorer will run a broker process with higher rights that can use the current user's permissions to take actions that would otherwise be prohibited when rendering content inside the Protected Mode sandbox. https://blogs.msdn.microsoft.com/ieinternals/2009/11/30/understanding-the-protected-mode-elevation-dialog/.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)
Attacker's goals:

When an add-on is running inside Protected Mode attempts to launch a broker process, this key is checked to determine how the process should be launched. Attackers may change this value to make the process launch with higher privileges.

Investigative actions:

Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Tampering with Internet Explorer Protected Mode default configuration Medium (parent: Informational)
  • Tampering with Internet Explorer Protected Mode specific app configuration Informational