UAC Bypass Using IDiagnostic Profile - File

 Original Source: [Sigma source]
Title: UAC Bypass Using IDiagnostic Profile - File
Status: test
Description:Detects the creation of a file by "dllhost.exe" in System32 directory part of "IDiagnosticProfileUAC" UAC bypass technique
References:
  -https://github.com/Wh04m1001/IDiagnosticProfileUAC
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-03
modified:None
Tags:
  • -'attack.execution'
  • -'attack.privilege-escalation'
  • -'attack.t1548.002'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image|endswith: '\DllHost.exe'
    TargetFilename|startswith: 'C:\Windows\System32\'
    TargetFilename|endswith: '.dll'
  condition:selection
Falsepositives:
  -Unknown
Level: high