This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
CMSTP UAC Bypass via COM Object Access
Original Source:
[Sigma source]
Title:
CMSTP UAC Bypass via COM Object Access
Status:
stable
Description:
Detects UAC Bypass Attempt Using Microsoft Connection Manager Profile Installer Autoelevate-capable COM Objects (e.g. UACMe ID of 41, 43, 58 or 65)
References:
-https://web.archive.org/web/20190720093911/http://www.endurant.io/cmstp/detecting-cmstp-enabled-code-execution-and-uac-bypass-with-sysmon/
-https://twitter.com/hFireF0X/status/897640081053364225
-https://medium.com/falconforce/falconfriday-detecting-uac-bypasses-0xff16-86c2a9107abf
-https://github.com/hfiref0x/UACME
Author:
Nik Seetharaman, Christian Burkard (Nextron Systems)
Date:
2019-07-31
modified:
2024-12-01
Tags:
-'attack.execution'
-'attack.privilege-escalation'
-'attack.stealth'
-'attack.t1548.002'
-'attack.t1218.003'
-'attack.g0069'
-'car.2019-04-001'
Logsource:
category: process_creation
product: windows
Detection:
selection:
ParentImage|endswith
:
'\DllHost.exe'
ParentCommandLine|contains
:
-' /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}'
-' /Processid:{3E000D72-A845-4CD9-BD83-80C07C3B881F}'
-' /Processid:{BD54C901-076B-434E-B6C7-17C531F4AB41}'
-' /Processid:{D2E7041B-2927-42FB-8E9F-7CE93B6DC937}'
-' /Processid:{E9495B87-D950-4AB5-87A5-FF6D70BF3E90}'
IntegrityLevel
:
-'High'
-'System'
-'S-1-16-16384'
-'S-1-16-12288'
condition
:
selection
Falsepositives:
-Legitimate CMSTP use (unlikely in modern enterprise environments)
Level:
high