ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1548.002×

11 examples

TechniqueUsed byProcedure example
T1548.002
Bypass User Account Control
GroupAPT38

APT38 has used the legitimate application `ieinstal.exe` to bypass UAC.

T1548.002
Bypass User Account Control
GroupPatchwork

Patchwork bypassed User Access Control (UAC).

T1548.002
Bypass User Account Control
GroupEvilnum

Evilnum has used PowerShell to bypass UAC.

T1548.002
Bypass User Account Control
GroupMuddyWater

MuddyWater uses various techniques to bypass UAC.

T1548.002
Bypass User Account Control
GroupAPT37

APT37 has a function in the initial dropper to bypass Windows UAC in order to execute the next payload with higher privileges.

T1548.002
Bypass User Account Control
GroupAPT29

APT29 has bypassed UAC.

T1548.002
Bypass User Account Control
GroupMedusa Group

Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface.

T1548.002
Bypass User Account Control
GroupBRONZE BUTLER

BRONZE BUTLER has used a Windows 10 specific tool and xxmm to bypass UAC for privilege escalation.

T1548.002
Bypass User Account Control
GroupEarth Lusca

Earth Lusca has used the Fodhelper UAC bypass technique to gain elevated privileges.

T1548.002
Bypass User Account Control
GroupCobalt Group

Cobalt Group has bypassed UAC.

T1548.002
Bypass User Account Control
GroupThreat Group-3390

A Threat Group-3390 tool can use a public UAC bypass method to elevate privileges.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.