<<< Hide Navigation Hide TOC >>>
UAC Bypass Using Iscsicpl - ImageLoad (9ed5959a-c43c-4c59-84e3-d28628429456)
Detects the "iscsicpl.exe" UAC bypass technique that leverages a DLL Search Order hijacking technique to load a custom DLL's from temp or a any user controlled location in the users %PATH%
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
UAC Bypass Using Iscsicpl - ImageLoad (9ed5959a-c43c-4c59-84e3-d28628429456) | Sigma-Rules | Bypass User Account Control - T1548.002 (120d5519-3098-4e1c-9191-2aa61232f073) | Attack Pattern | 1 |
Abuse Elevation Control Mechanism - T1548 (67720091-eee3-4d2d-ae16-8264567f6f5b) | Attack Pattern | Bypass User Account Control - T1548.002 (120d5519-3098-4e1c-9191-2aa61232f073) | Attack Pattern | 2 |