Analytics BIOC
Informational
✕
Tampering with the Windows User Account Controls (UAC) configuration
EnableLUA specifies whether Windows User Account Controls (UAC) notifies the user when programs try to modify the computer. UAC was formerly known as Limited User Account (LUA).
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002)
Attacker's goals:
Gain higher privileges by bypassing the User Account Control (UAC).
Investigative actions:
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
3 variations:
- Tampering with the Windows User Account Controls (UAC) configuration by a remote host Medium (parent: Informational)
- Tampering with the Windows User Account Controls (UAC) configuration Low (parent: Informational)
- Tampering with the Windows User Account Controls (UAC) configuration Low (parent: Informational)