T1548.002 · Bypass User Account Control
Sub-técnica de T1548 · Abuse Elevation Control Mechanism.
Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user ...
¿Cómo detectarlo y mitigarlo?
Técnicas relacionadas
PowerShell Profile T1546.006
LC_LOAD_DYLIB Addition T1548.003
Sudo and Sudo Caching T1546.011
Application Shimming T1611
Escape to Host T1546.005
Trap T1548
Abuse Elevation Control Mechanism T1548.001
Setuid and Setgid
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.