BIOC
Medium
✕
Bypass UAC using the IsolatedCommand Registry value
IsolatedCommand is a Registry value known to be altered by attackers to allow themselves to run their malware with elevated privileges.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Privilege Escalation
- Status:
- Enabled
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002)
Indicator:
Registry action type = create_registry_key , set_registry_value AND registry data != "%1" %* AND registry key name = *\exefile\shell\runas\command* AND registry value name = IsolatedCommand Host host os = windows
Preventable: yes