BIOC
Medium
✕
Manipulation of the sticky keys file
Possible login bypass attack.
- Module:
- Platform Analytics
- Agent event type:
- File
- Category:
- Privilege Escalation
- Status:
- Enabled
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Event Triggered Execution: Accessibility Features (T1546.008)
Indicator:
File action type = create , write AND file path = *:\Windows\System32 , *:\Windows\Syswow64 AND file name = sethc.exe
Preventable: yes