<<< Hide Navigation Hide TOC >>>
UAC Bypass Using ChangePK and SLUI (503d581c-7df0-4bbe-b9be-5840c0ecc1fc)
Detects an UAC bypass that uses changepk.exe and slui.exe (UACMe 61)
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
UAC Bypass Using ChangePK and SLUI (503d581c-7df0-4bbe-b9be-5840c0ecc1fc) | Sigma-Rules | Bypass User Account Control - T1548.002 (120d5519-3098-4e1c-9191-2aa61232f073) | Attack Pattern | 1 |
Abuse Elevation Control Mechanism - T1548 (67720091-eee3-4d2d-ae16-8264567f6f5b) | Attack Pattern | Bypass User Account Control - T1548.002 (120d5519-3098-4e1c-9191-2aa61232f073) | Attack Pattern | 2 |