Free kit

Free AI Tabletop Exercise Kit for SMBs

Sign up for the Cyber Defense & AI Brief and get it free.

Get the free kit

UC-L3-014

Privilege Escalation via UAC Bypass

Sysmon Event ID 1

Use case development / Detect Insider Threats / Detect Privilege Abuse

sigma

Detection rule

title: UAC Bypass via fodhelper
status: experimental
description: Detects UAC bypass using fodhelper.exe
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    ParentImage|endswith: '\fodhelper.exe'
    IntegrityLevel: 'High'
  condition: selection
falsepositives:
  - None expected
level: high
tags:
  - attack.privilege_escalation
  - attack.t1548

Test cases

  • Execute UAC bypass via fodhelper

False positive guidance

No known false positives.

Detection course