UAC Disabled

 Original Source: [Sigma source]
Title: UAC Disabled
Status: stable
Description:Detects when an attacker tries to disable User Account Control (UAC) by setting the registry value "EnableLUA" to 0.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/7e11e9b79583545f208a6dc3fa062f2ed443d999/atomics/T1548.002/T1548.002.md
Author: frack113
Date: 2022-01-05
modified:2024-05-10
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1548.002'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|contains: '\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA'
    Details: 'DWORD (0x00000000)'
  condition:selection
Falsepositives:
  -Unknown
Level: medium