Sub-technique of T1548 Abuse Elevation Control Mechanism.View on attack.mitre.org
Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action.
If the UAC protection level of a computer is set to anything but the highest level, certain Windows programs can elevate privileges or execute some elevated Component Object Model objects without prompting the user through the UAC notification box. An example of this is use of Rundll32 to load a specifically crafted DLL which loads an auto-elevated Component Object Model object and performs a file operation in a protected directory which would typically require elevated access. Malicious software may also be injected into a trusted process to gain elevated privileges without prompting a user.
Many methods have been discovered to bypass UAC. The Github readme page for UACME contains an extensive list of methods that have been discovered and implemented, but may not be a comprehensive list of bypasses. Additional bypass methods are regularly discovered and some used in the wild, such as:
* eventvwr.exe can auto-elevate and execute a specified binary or script.
Another bypass is possible through some lateral movement techniques if credentials for an account with administrator privileges are known, since UAC is a single system security mechanism, and the privilege or integrity of a process running on one system will be unknown on remote systems and default to high integrity.
Rules on DetectionCode tagged with T1548.002.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Disable UAC Remote Restriction | TTP | NULL | Sysmon EventID 13 |
| Disabling Remote User Account Control | TTP | NULL | Sysmon EventID 13 |
| Eventvwr UAC Bypass | TTP | NULL | Sysmon EventID 13 |
| FodHelper UAC Bypass | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| NET Profiler UAC bypass | TTP | NULL | Sysmon EventID 13 |
| Sdclt UAC Bypass | TTP | NULL | Sysmon EventID 12, Sysmon EventID 13 |
| SilentCleanup UAC Bypass | TTP | NULL | Sysmon EventID 13 |
| SLUI RunAs Elevated | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| SLUI Spawning a Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| UAC Bypass MMC Load Unsigned Dll | TTP | NULL | Sysmon EventID 7 |
| Windows Bypass UAC via Pkgmgr Tool | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows ComputerDefaults Spawning a Process | TTP | NULL | Sysmon EventID 1 |
| Windows DISM Install PowerShell Web Access | TTP | NULL | Windows Event Log Security 4688, Sysmon EventID 1 |
| Windows Mock Trusted Directory MSC File Creation | TTP | NULL | Sysmon EventID 11 |
| Windows Suspicious Child Process of Consent.EXE | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows UAC Bypass Suspicious Child Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows UAC Bypass Suspicious Escalation Behavior | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 1 |
| WSReset UAC Bypass | TTP | NULL | Sysmon EventID 12, Sysmon EventID 13 |
| Used by | Procedure example |
|---|---|
| GroupAPT29 | APT29 has bypassed UAC. |
| GroupAPT37 | APT37 has a function in the initial dropper to bypass Windows UAC in order to execute the next payload with higher privileges. |
| GroupAPT38 | APT38 has used the legitimate application `ieinstal.exe` to bypass UAC. |
| GroupBRONZE BUTLER | BRONZE BUTLER has used a Windows 10 specific tool and xxmm to bypass UAC for privilege escalation. |
| GroupCobalt Group | Cobalt Group has bypassed UAC. |
| GroupEarth Lusca | Earth Lusca has used the Fodhelper UAC bypass technique to gain elevated privileges. |
| GroupEvilnum | Evilnum has used PowerShell to bypass UAC. |
| GroupMedusa Group | Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface. |
| Used by | Procedure example |
|---|---|
| MalwareAppleJeus | AppleJeus has presented the user with a UAC prompt to elevate privileges while installing. |
| MalwareAutoIt backdoor | AutoIt backdoor attempts to escalate privileges by bypassing User Access Control. |
| MalwareAvaddon | Avaddon bypasses UAC using the CMSTPLUA COM interface. |
| MalwareBad Rabbit | Bad Rabbit has attempted to bypass UAC and gain elevated administrative privileges. |
| MalwareBADHATCH | BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC. |
| MalwareBitPaymer | BitPaymer can suppress UAC prompts by setting the |
| MalwareBlackCat | BlackCat can bypass UAC to escalate privileges. |
| MalwareBlackEnergy | BlackEnergy attempts to bypass default User Access Control (UAC) settings by exploiting a backward-compatibility setting found in Windows 7 and later. |
| Used by | Procedure example |
|---|---|
| CampaignOperation Honeybee | During Operation Honeybee, the threat actors used the malicious NTWDBLIB.DLL and `cliconfig.exe` to bypass UAC protections. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.