Detection rules › Sigma

UAC Bypass Tools Using ComputerDefaults

Status
test
Severity
high
Log source
category process_creation, product windows
Author
Christian Burkard (Nextron Systems)
Source
github.com/SigmaHQ/sigma

Detects tools such as UACMe used to bypass UAC with computerdefaults.exe (UACMe 59)

MITRE ATT&CK coverage

Telemetry coverage

Rule body

title: UAC Bypass Tools Using ComputerDefaults
id: 3c05e90d-7eba-4324-9972-5d7f711a60a8
status: test
description: Detects tools such as UACMe used to bypass UAC with computerdefaults.exe (UACMe 59)
references:
    - https://github.com/hfiref0x/UACME
author: Christian Burkard (Nextron Systems)
date: 2021-08-31
modified: 2024-12-01
tags:
    - attack.privilege-escalation
    - attack.t1548.002
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        IntegrityLevel:
            - 'High'
            - 'System'
            - 'S-1-16-16384' # System
            - 'S-1-16-12288' # High
        Image: 'C:\Windows\System32\ComputerDefaults.exe'
    filter:
        ParentImage|contains:
            - ':\Windows\System32'
            - ':\Program Files'
    condition: selection and not filter
falsepositives:
    - Unknown
level: high

Stages and Predicates

Stage 0: condition

selection and not filter

Stage 1: selection

selection:
    IntegrityLevel:
        - 'High'
        - 'System'
        - 'S-1-16-16384'
        - 'S-1-16-12288'
    Image: 'C:\Windows\System32\ComputerDefaults.exe'

Stage 2: not filter

filter:
    ParentImage|contains:
        - ':\Windows\System32'
        - ':\Program Files'

Exclusions

The rule actively suppresses these predicates.

FieldKindExcluded valuesSearch
ParentImagematch:\Program Filesexcludes:ParentImage field:"ParentImage" value:":\Program Files"
ParentImagematch:\Windows\System32excludes:ParentImage field:"ParentImage" value:":\Windows\System32"

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
Imageeq
  • C:\Windows\System32\ComputerDefaults.exe
field:"Image" kind:eq value:"C:\Windows\System32\ComputerDefaults.exe"
IntegrityLeveleq
  • High corpus 21 (sigma 17, kusto 3, splunk 1)
  • S-1-16-12288 corpus 21 (sigma 17, kusto 3, splunk 1)
  • S-1-16-16384 corpus 30 (sigma 22, splunk 4, elastic 3, kusto 1)
  • System corpus 30 (sigma 22, splunk 4, elastic 3, kusto 1)
field:"IntegrityLevel" kind:eq