UAC Bypass Using Iscsicpl - ImageLoad

 Original Source: [Sigma source]
Title: UAC Bypass Using Iscsicpl - ImageLoad
Status: test
Description:Detects the "iscsicpl.exe" UAC bypass technique that leverages a DLL Search Order hijacking technique to load a custom DLL's from temp or a any user controlled location in the users %PATH%
References:
  -https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC
  -https://twitter.com/wdormann/status/1547583317410607110
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-17
modified:2022-07-25
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1548.002'
Logsource:
  • product: windows
  • category: image_load
Detection:
  selection:
    Image: 'C:\Windows\SysWOW64\iscsicpl.exe'
    ImageLoaded|endswith: '\iscsiexe.dll'
  filter:
    ImageLoaded|contains|all:
      -'C:\Windows\'
      -'iscsiexe.dll'

  condition:selection and not filter
Falsepositives:
  -Unknown
Level: high