Bypass UAC Using DelegateExecute

 Original Source: [Sigma source]
Title: Bypass UAC Using DelegateExecute
Status: test
Description:Bypasses User Account Control using a fileless method
References:
  -https://learn.microsoft.com/en-us/windows/win32/api/shobjidl_core/nn-shobjidl_core-iexecutecommand
  -https://devblogs.microsoft.com/oldnewthing/20100312-01/?p=14623
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1548.002/T1548.002.md#atomic-test-7---bypass-uac-using-sdclt-delegateexecute
Author: frack113
Date: 2022-01-05
modified:2023-08-17
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1548.002'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|endswith: '\open\command\DelegateExecute'
    Details: '(Empty)'
  condition:selection
Falsepositives:
  -Unknown
Level: high