{"id":"4ac47ed3-44c2-4b1f-9d51-bf46e8914126","title":"TrustedPath UAC Bypass Pattern","description":"Detects indicators of a UAC bypass method by mocking directories","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-08-27","modified":"2025-06-17","tags":["attack.privilege-escalation","attack.t1548.002"],"technique_ids":["T1548.002"],"logsource":{"category":"process_creation","product":"windows"},"falsepositives":["Unknown"],"references":["https://medium.com/tenable-techblog/uac-bypass-by-mocking-trusted-directories-24a96675f6e","https://www.wietzebeukema.nl/blog/hijacking-dlls-in-windows","https://github.com/netero1010/TrustedPath-UACBypass-BOF","https://x.com/Wietze/status/1933495426952421843"],"source_path":"rules/windows/process_creation/proc_creation_win_uac_bypass_trustedpath.yml","source_sha256":"4d432a87e46c12f517b9d9ad25daa07f1db15a73b2891342a4818c58c1997327","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_uac_bypass_trustedpath.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: TrustedPath UAC Bypass Pattern\nid: 4ac47ed3-44c2-4b1f-9d51-bf46e8914126\nrelated:\n    - id: 0cbe38c0-270c-41d9-ab79-6e5a9a669290\n      type: similar\nstatus: test\ndescription: Detects indicators of a UAC bypass method by mocking directories\nreferences:\n    - https://medium.com/tenable-techblog/uac-bypass-by-mocking-trusted-directories-24a96675f6e\n    - https://www.wietzebeukema.nl/blog/hijacking-dlls-in-windows\n    - https://github.com/netero1010/TrustedPath-UACBypass-BOF\n    - https://x.com/Wietze/status/1933495426952421843\nauthor: Florian Roth (Nextron Systems)\ndate: 2021-08-27\nmodified: 2025-06-17\ntags:\n    - attack.privilege-escalation\n    - attack.t1548.002\nlogsource:\n    category: process_creation\n    product: windows\ndetection:\n    selection:\n        Image|contains:\n            - 'C:\\Windows \\System32\\'\n            - 'C:\\Windows \\SysWOW64\\'\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: critical\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1548.002","id":"T1548.002","name":"Bypass User Account Control","page":"techniques/enterprise/T1548.002/"}],"data_path":"data/detection-rules/4ac47ed3-44c2-4b1f-9d51-bf46e8914126.json","kind":"sigma"}
