UC-L3-014
Privilege Escalation via UAC Bypass
Sysmon Event ID 1
Use case development / Detect Insider Threats / Detect Privilege Abuse
sigma
Detection rule
title: UAC Bypass via fodhelper
status: experimental
description: Detects UAC bypass using fodhelper.exe
logsource:
product: windows
category: process_creation
detection:
selection:
ParentImage|endswith: '\fodhelper.exe'
IntegrityLevel: 'High'
condition: selection
falsepositives:
- None expected
level: high
tags:
- attack.privilege_escalation
- attack.t1548Test cases
- Execute UAC bypass via fodhelper
False positive guidance
No known false positives.