BIOC Medium

Manipulation of the sticky keys file

Possible login bypass attack.

Module:
Platform Analytics
Agent event type:
File
Category:
Privilege Escalation
Status:
Enabled
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Event Triggered Execution: Accessibility Features (T1546.008)
Indicator:

File action type = create , write AND file path = *:\Windows\System32 , *:\Windows\Syswow64 AND file name = sethc.exe

Preventable: yes