UAC Bypass via Sdclt

 Original Source: [Sigma source]
Title: UAC Bypass via Sdclt
Status: test
Description:Detects the pattern of UAC Bypass using registry key manipulation of sdclt.exe (e.g. UACMe 53)
References:
  -https://enigma0x3.net/2017/03/17/fileless-uac-bypass-using-sdclt-exe/
  -https://github.com/hfiref0x/UACME
Author: Omer Yampel, Christian Burkard (Nextron Systems)
Date: 2017-03-17
modified:2023-08-17
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1548.002'
  • -'car.2019-04-001'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection1:
    TargetObject|endswith: 'Software\Classes\exefile\shell\runas\command\isolatedCommand'
  selection2:
    TargetObject|endswith: 'Software\Classes\Folder\shell\open\command\SymbolicLinkValue'
    Details|re: '-1[0-9]{3}\\Software\\Classes\\'
  condition:1 of selection*
Falsepositives:
  -Unknown
Level: high