BIOC Medium

Possible UAC bypass via Event Viewer

Eventvwr.exe normally only spawns mmc.exe. Attackers may use it for bypassing UAC (User Account Control) by having it spawn a different process.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
File Privilege Manipulation
Status:
Enabled
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002)
Indicator:

Process action type = execution AND target process name != mmc.exe Process initiated by = eventvwr.exe , os parent name = eventvwr.exe Host host os = windows

Preventable: yes