CMSTP UAC Bypass via COM Object Access

 Original Source: [Sigma source]
Title: CMSTP UAC Bypass via COM Object Access
Status: stable
Description:Detects UAC Bypass Attempt Using Microsoft Connection Manager Profile Installer Autoelevate-capable COM Objects (e.g. UACMe ID of 41, 43, 58 or 65)
References:
  -https://web.archive.org/web/20190720093911/http://www.endurant.io/cmstp/detecting-cmstp-enabled-code-execution-and-uac-bypass-with-sysmon/
  -https://twitter.com/hFireF0X/status/897640081053364225
  -https://medium.com/falconforce/falconfriday-detecting-uac-bypasses-0xff16-86c2a9107abf
  -https://github.com/hfiref0x/UACME
Author: Nik Seetharaman, Christian Burkard (Nextron Systems)
Date: 2019-07-31
modified:2024-12-01
Tags:
  • -'attack.execution'
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1548.002'
  • -'attack.t1218.003'
  • -'attack.g0069'
  • -'car.2019-04-001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\DllHost.exe'
    ParentCommandLine|contains:
      -' /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}'
      -' /Processid:{3E000D72-A845-4CD9-BD83-80C07C3B881F}'
      -' /Processid:{BD54C901-076B-434E-B6C7-17C531F4AB41}'
      -' /Processid:{D2E7041B-2927-42FB-8E9F-7CE93B6DC937}'
      -' /Processid:{E9495B87-D950-4AB5-87A5-FF6D70BF3E90}'

    IntegrityLevel:
      -'High'
      -'System'
      -'S-1-16-16384'
      -'S-1-16-12288'

  condition:selection
Falsepositives:
  -Legitimate CMSTP use (unlikely in modern enterprise environments)
Level: high