1200KM / detection
T1548.002 Bypass User Account Control — Detection Rules
Detection workspace for T1548.002 Bypass User Account Control: 56 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- UAC Bypass Using Consent and Comctl32 - File · test · high · {"category":"file_event","product":"windows"}
- UAC Bypass Using .NET Code Profiler on MMC · test · high · {"category":"file_event","product":"windows"}
- UAC Bypass Using IDiagnostic Profile - File · test · high · {"product":"windows","category":"file_event"}
- UAC Bypass Using IEInstal - File · test · high · {"category":"file_event","product":"windows"}
- UAC Bypass Using MSConfig Token Modification - File · test · high · {"category":"file_event","product":"windows"}
- UAC Bypass Using NTFS Reparse Point - File · test · high · {"category":"file_event","product":"windows"}
- UAC Bypass Abusing Winsat Path Parsing - File · test · high · {"category":"file_event","product":"windows"}
- UAC Bypass Using Windows Media Player - File · test · high · {"category":"file_event","product":"windows"}
- UAC Bypass Using Iscsicpl - ImageLoad · test · high · {"product":"windows","category":"image_load"}
- UAC Bypass With Fake DLL · test · high · {"category":"image_load","product":"windows"}
- Trusted Path Bypass via Windows Directory Spoofing · experimental · high · {"category":"image_load","product":"windows"}
- HackTool - WinPwn Execution - ScriptBlock · test · high · {"category":"ps_script","product":"windows","definition":"Requirements: Script Block Logging must be enabled"}
- Function Call From Undocumented COM Interface EditionUpgradeManager · test · medium · {"category":"process_access","product":"windows"}
- UAC Bypass Using WOW64 Logger DLL Hijack · test · high · {"category":"process_access","product":"windows"}
- PowerShell Web Access Feature Enabled Via DISM · test · high · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Event Viewer Child Process · test · high · {"category":"process_creation","product":"windows"}
- Explorer NOUACCHECK Flag · test · high · {"category":"process_creation","product":"windows"}
- HackTool - Empire PowerShell UAC Bypass · stable · critical · {"category":"process_creation","product":"windows"}
- HackTool - UACMe Akagi Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - WinPwn Execution · test · high · {"category":"process_creation","product":"windows"}
- Sdclt Child Processes · test · medium · {"category":"process_creation","product":"windows"}
- Always Install Elevated Windows Installer · test · medium · {"product":"windows","category":"process_creation"}
- Always Install Elevated MSI Spawned Cmd And Powershell · test · medium · {"product":"windows","category":"process_creation"}
- Registry Modification of MS-settings Protocol Handler · test · medium · {"category":"process_creation","product":"windows"}
- UAC Bypass Using ChangePK and SLUI · test · high · {"category":"process_creation","product":"windows"}
- UAC Bypass Using Disk Cleanup · test · high · {"category":"process_creation","product":"windows"}
- Bypass UAC via CMSTP · test · high · {"category":"process_creation","product":"windows"}
- CMSTP UAC Bypass via COM Object Access · stable · high · {"category":"process_creation","product":"windows"}
- UAC Bypass Tools Using ComputerDefaults · test · high · {"category":"process_creation","product":"windows"}
- UAC Bypass Using Consent and Comctl32 - Process · test · high · {"category":"process_creation","product":"windows"}
- UAC Bypass Using DismHost · test · high · {"category":"process_creation","product":"windows"}
- Bypass UAC via Fodhelper.exe · test · high · {"category":"process_creation","product":"windows"}
- UAC Bypass via ICMLuaUtil · test · high · {"category":"process_creation","product":"windows"}
- UAC Bypass Using IDiagnostic Profile · test · high · {"category":"process_creation","product":"windows"}
- UAC Bypass Using IEInstal - Process · test · high · {"category":"process_creation","product":"windows"}
- UAC Bypass Using MSConfig Token Modification - Process · test · high · {"category":"process_creation","product":"windows"}
- UAC Bypass Using NTFS Reparse Point - Process · test · high · {"category":"process_creation","product":"windows"}
- UAC Bypass Using PkgMgr and DISM · test · high · {"category":"process_creation","product":"windows"}
- Potential UAC Bypass Via Sdclt.EXE · test · medium · {"category":"process_creation","product":"windows"}
- TrustedPath UAC Bypass Pattern · test · critical · {"category":"process_creation","product":"windows"}
- UAC Bypass Abusing Winsat Path Parsing - Process · test · high · {"category":"process_creation","product":"windows"}
- UAC Bypass Using Windows Media Player - Process · test · high · {"category":"process_creation","product":"windows"}
- Bypass UAC via WSReset.exe · test · high · {"category":"process_creation","product":"windows"}
- UAC Bypass WSReset · test · high · {"category":"process_creation","product":"windows"}
- UAC Bypass Via Wsreset · test · high · {"category":"registry_event","product":"windows"}
- Shell Open Registry Keys Manipulation · test · high · {"category":"registry_event","product":"windows"}
- Bypass UAC Using DelegateExecute · test · high · {"category":"registry_set","product":"windows"}
- Bypass UAC Using SilentCleanup Task · test · high · {"category":"registry_set","product":"windows"}
- Suspicious Shell Open Command Registry Modification · experimental · medium · {"category":"registry_set","product":"windows"}
- UAC Bypass via Event Viewer · test · high · {"product":"windows","category":"registry_set"}
- UAC Bypass via Sdclt · test · high · {"category":"registry_set","product":"windows"}
- UAC Bypass Abusing Winsat Path Parsing - Registry · test · high · {"category":"registry_set","product":"windows"}
- UAC Bypass Using Windows Media Player - Registry · test · high · {"category":"registry_set","product":"windows"}
- UAC Disabled · stable · medium · {"category":"registry_set","product":"windows"}
- UAC Notification Disabled · test · medium · {"category":"registry_set","product":"windows"}
- UAC Secure Desktop Prompt Disabled · test · medium · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
T1548.002 Bypass User Account Control
MATCH(process_or_registry_pattern IN known_uac_bypass_patterns) -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0388 Detection Strategy for T1548.002 – Bypass User Account Control (UAC)
AN1094 Analytic 1094
Detects a multi-event behavior chain involving UAC bypass attempts via known auto-elevated binaries (e.g., eventvwr.exe, sdclt.exe), unauthorized Registry changes to UAC-related keys, and anomalous process execution with elevated privileges but lacking standard parent-child lineage. Suspicious patterns include invocation of auto-elevated COM objects or manipulation of isolatedCommand Registry entries without consent prompts.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.