1200KM / simulation
T1548.002 Bypass User Account Control — Attack Simulation
Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they…
Technique description
Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Disable UAC notification via registry keys
Procedure 160a7c77-b00e-4111-9e45-7c2a44eda3fd; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - UAC Bypass DiskCleanup technique
Procedure 1ed67900-66cd-4b09-b546-2a0ef4431a0c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- UACME Bypass Method 56
Procedure 235ec031-cd2d-465d-a7ae-68bab281e80e; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Disable UAC admin consent prompt via ConsentPromptBehaviorAdmin registry key
Procedure 251c5936-569f-42f4-9ac2-87a173b9e9b8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Bypass UAC using SilentCleanup task
Procedure 28104f8a-4ff1-4582-bcf6-699dce156608; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WinPwn - UAC Bypass DccwBypassUAC technique
Procedure 2b61977b-ae2d-4ae4-89cb-5c36c89586be; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Warzone/AveMaria RAT style UAC bypass
Procedure 350b8e4b-520b-4673-bac2-d15aa1862128; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- UAC Bypass with WSReset Registry Modification
Procedure 3b96673f-9c92-40f1-8a3e-ca060846f8d9; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Bypass UAC using sdclt DelegateExecute
Procedure 3be891eb-4608-4173-87e8-78b494c029b7; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Bypass UAC using ComputerDefaults (PowerShell)
Procedure 3c51abf2-44bf-42d8-9111-dc96ff66750f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Bypass UAC using Fodhelper - PowerShell
Procedure 3f627297-6c38-4e7d-a278-fc2563eaaeaa; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Bypass UAC using Event Viewer (cmd)
Procedure 5073adf8-9a50-4bd9-b298-a9bd2ead8af9; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- UACME Bypass Method 39
Procedure 56163687-081f-47da-bb9c-7b231c5585cf; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Bypass UAC using Fodhelper
Procedure 58f641ea-12e3-499a-b684-44dee46bd182; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- UACME Bypass Method 34
Procedure 695b2dac-423e-448e-b6ef-5b88e93011d6; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- UACME Bypass Method 61
Procedure 7825b576-744c-4555-856d-caf3460dc236; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Disable UAC - Switch to the secure desktop when prompting for elevation via registry key
Procedure 85f3a526-4cfa-4fe7-98c1-dea99be025c7; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- UACME Bypass Method 23
Procedure 8ceab7a2-563a-47d2-b5ba-0995211128d7; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - UAC Magic
Procedure 964d8bf8-37bc-4fd3-ba36-ad13761ebbcc; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Disable UAC using reg.exe
Procedure 9e8af564-53ec-407e-aaa8-3cb20c3af7f9; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Bypass UAC using Event Viewer (PowerShell)
Procedure a6ce9acf-842a-4af6-8f79-539be7608e2b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Disable ConsentPromptBehaviorAdmin via registry keys
Procedure a768aaa2-2442-475c-8990-69cf33af0f4e; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- UACME Bypass Method 31
Procedure b0f76240-9f33-4d34-90e8-3a7d501beb15; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- UAC bypassed by Utilizing ProgIDs registry.
Procedure b6f4645c-34ea-4c7c-98f2-d5a2747efb08; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- UACME Bypass Method 59
Procedure dfb1b667-4bb8-4a63-a85e-29936ea75f29; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- UACME Bypass Method 33
Procedure e514bb03-f71c-4b22-9092-9f961ec6fb03; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - UAC Bypass ccmstp technique
Procedure f3c145f9-3c8d-422c-bd99-296a17a8f567; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Bypass UAC by Mocking Trusted Directories
Procedure f7a35090-6f7f-4f64-bb47-d657bf5b10c1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.