UAC Bypass via ICMLuaUtil

 Original Source: [Sigma source]
Title: UAC Bypass via ICMLuaUtil
Status: test
Description:Detects the pattern of UAC Bypass using ICMLuaUtil Elevated COM interface
References:
  -https://www.elastic.co/guide/en/security/current/uac-bypass-via-icmluautil-elevated-com-interface.html
Author: Florian Roth (Nextron Systems), Elastic (idea)
Date: 2022-09-13
modified:2022-09-27
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1548.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\dllhost.exe'
    ParentCommandLine|contains:
      -'/Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}'
      -'/Processid:{D2E7041B-2927-42FB-8E9F-7CE93B6DC937}'

  filter:
Image|endswith:'\WerFault.exe' OriginalFileName:'WerFault.exe'   condition:selection and not filter
Falsepositives:
  -Unknown
Level: high