BIOC Medium

UAC bypass using the changepk.exe Registry key

Attackers may use the changepk.exe built-in Windows tool to bypass Windows UAC by modifying Registry keys.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Privilege Escalation
Status:
Enabled
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002)
Indicator:

Registry registry key name = *Launcher.SystemSettings\Shell\Open\Command* AND action type = set_registry_value Host host os = windows

Preventable: yes