HackTool - Empire PowerShell UAC Bypass

 Original Source: [Sigma source]
Title: HackTool - Empire PowerShell UAC Bypass
Status: stable
Description:Detects some Empire PowerShell UAC bypass methods
References:
  -https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/data/module_source/privesc/Invoke-EventVwrBypass.ps1#L64
  -https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/data/module_source/privesc/Invoke-FodHelperBypass.ps1#L64
Author: Ecco
Date: 2019-08-30
modified:2023-02-21
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1548.002'
  • -'car.2019-04-001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains:
      -' -NoP -NonI -w Hidden -c $x=$((gp HKCU:Software\Microsoft\Windows Update).Update)'
      -' -NoP -NonI -c $x=$((gp HKCU:Software\Microsoft\Windows Update).Update);'

  condition:selection
Falsepositives:
  -Unknown
Level: critical