BIOC Medium

Bypass UAC using the control.exe Registry key

Control.exe is a Registry key known to be altered by attackers to allow themselves to run their malware with elevated privileges.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Privilege Escalation
Status:
Enabled
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002)
Indicator:

Registry action type = create_registry_key , set_registry_value AND registry data != "%1" %* AND registry key name = *currentVersion\app paths\control.exe* Host host os = windows

Preventable: yes