Regedit as Trusted Installer (883835a7-df45-43e4-bf1d-4268768afda4)
Detects a regedit started with TrustedInstaller privileges or by ProcessHacker.exe
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Regedit as Trusted Installer (883835a7-df45-43e4-bf1d-4268768afda4) | Sigma-Rules | Abuse Elevation Control Mechanism - T1548 (67720091-eee3-4d2d-ae16-8264567f6f5b) | Attack Pattern | 1 |