logo

Exploring Windows UAC Bypasses: Techniques and Detection Strategies

ID: 9d72bc0c-d680-5d1a-93bd-b3ebff2404f6

STIX ID: report--9d72bc0c-d680-5d1a-93bd-b3ebff2404f6

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2023-05-15

Date Updated: 2026-04-27

...
...

This blog-style technical report analyzes Windows User Account Control (UAC) bypass techniques (registry/environment manipulation, DLL hijacking, elevated COM interfaces, token attributes), demonstrates detection approaches including EQL/KQL examples and Elastic Endpoint features, discusses common evasion tactics, and cites observed use by malware and ransomware families (e.g., Glupteba, DarkSide, LockBit). It emphasizes focusing detections on core primitives (token attributes, registry/DLL redirection, IFileOperation activity) for broader coverage against varied bypass implementations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.