BIOC
Medium
✕
Possible UAC bypass via Event Viewer
Eventvwr.exe normally only spawns mmc.exe. Attackers may use it for bypassing UAC (User Account Control) by having it spawn a different process.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- File Privilege Manipulation
- Status:
- Enabled
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002)
Indicator:
Process action type = execution AND target process name != mmc.exe Process initiated by = eventvwr.exe , os parent name = eventvwr.exe Host host os = windows
Preventable: yes