Search and filter across all detection sources
22 rules
HackTool - Empire PowerShell UAC Bypass
Detects some Empire PowerShell UAC bypass methods
UAC Bypass via Event Viewer
Detects UAC bypass method using Windows event viewer
CMSTP Execution Process Creation
Detects various indicators of Microsoft Connection Manager Profile Installer execution
CMSTP Execution Process Access
UAC Bypass via Sdclt
Detects the pattern of UAC Bypass using registry key manipulation of sdclt.exe (e.g. UACMe 53)
Potentially Suspicious Event Viewer Child Process
Detects uncommon or suspicious child processes of "eventvwr.exe" which might indicate a UAC bypass attempt
CMSTP UAC Bypass via COM Object Access
Detects UAC Bypass Attempt Using Microsoft Connection Manager Profile Installer Autoelevate-capable COM Objects (e.g. UACMe ID of 41, 43, 58 or 65)
CMSTP App Paths Registry Key Modification
Detects modifications to the CMSTP App Paths registry key. This may indicate abuse of Microsoft Connection Manager Profile Installer (CMSTP) for arbitrary code execution or UAC bypass.