FORENSIA

ATT&CK · T1548.002 · sub-technique

Bypass User Account Control

Tactics: privilege-escalation

About

Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action. If the UAC protection level of a computer is set to anything but the highest level, certain Windows programs can elevate privileges or execute some elevated Component Object Model objects without prompting the user through the UAC notification box. An example of this is use of Rundll32 to load a specifically crafted DLL which loads an auto-elevated Component Object Model object and performs a file operation in a protected directory which would typically require elevated access. Malicious software may also be injected into a trusted process to gain elevated privileges without prompting a user. Many methods have been discovered to bypass UAC. The Github readme page for UACME contains an extensive list of methods that have been discovered and implemented, but may not be a comprehensive list of bypasses. Additional bypass methods are regularly discovered and some used in the wild, such as: * <code>eventvwr.exe</code> can auto-elevate and execute a specified binary or script. Another bypass is possible through some lateral movement techniques if credentials for an account with administrator privileges are known, since UAC is a single system security mechanism, and the privilege or integrity of a process running on one system will be unknown on remote systems and default to high integrity.

Used by actors

11 known groups

Software

51 malware/tools implement this

SakulaBlackEnergyUACMeAutoIt backdoorH1N1DowndelphShamoonWinnti for WindowsRTMCobalt StrikeFinFisherPupyZeroTKoadicPLAINTEEInvisiMoleQuasarRATUPPERCUTRemcosKONNIEmpirePoshC2ShimRatLokibotRamsayPipeMonCSPY DownloaderGrandoreiroBitPaymerAppleJeusBad RabbitWastedLockerSliverAvaddonClamblingRCSessionGelsemiumKOCTOPUSWarzoneRATSILENTTRINITYSaint BotBumblebeeBlackCatBADHATCHDarkGateRaspberry RobinCHIMNEYSWEEPLockBit 2.0LockBit 3.0QilinHTTPTroy

Corpus indicators tagged with this technique

449 indicators in the corpus carry T1548.002.

IndicatorTypeFamilySevSrc
2d5615acd1b0666995fd124fb72f2713c6609b5368350340288b52fecbdd016dsha256801
8419b1f0acca46d45f4c54c315c8cc4784946e07d547fe55187b928fa6c6b8f5sha256801
1c01ab1b59245f24ebdc5d9c414fcf4e2ce31f71f181522efc5a3d27476c8e21sha256801
2267d05dbd5e30c6dfcdde25731280dd755e689faa684bd21cfbef5281fd3e86sha256801
5562246e38f8935ba8b07350e6aaa44bc22abf37b77f49836fde5999f4b61cf1sha256801
7a370a9262d37de6a24706f92ff0cdded7202281a6ff3bf313721756226ebff9sha256801
12b41c07299d2535f7cdc194d97496acd944a9eb5d94b8d24b19291ed9d0830csha256801
19e0070e5009bd5b376b9be997361d0773dcb004200ee8fafe6c14b96cbd93e4sha256801
1d52ded1f3838a1eee849ae20b2fee6c84b183cc98abe7244365b9f34b925eeasha256801
66bf111030a2e22db575c0b7b7b677208745eef8b44265bb4259f41f126f1bf8sha256801
307964ed02f34bff4e40c5402cc936be07fd9957ef400596a4b3e2cd98c50ec1sha256801
4e035575be8fe350a9e36cf29dbbc8826af2f772672bd08c9e489a243cb90e31sha256801
ad0f892b7b99b68491ade4949ef6b575e64d9df5f84a53019b5c1e4eeb4c46a9sha256801
57edeb575862ce8d3bff2eb4d32d9e3fa1ffb7cb8f818e2e7fc6d25a506faea6sha256801
512adab2c69feaf026adfb12cbd7d2eb4fee746120491e44f476eebddcbb19f2sha256801
ccca11a6d5835999c40a0a5264084b3740633600c157754fad2ef59559e31736sha256801
7d8b6a64f7b65b281e7b5568929c6f96c62bbae9628162aabe7d8140a86d3de8sha256801
308351124c496d4f4effee65ab828506abf70385773c167ab1f32a7f030385achash802
3b6cb20891bce8602ce669187754871e402a1782031ef8b032cd007e3894bc5dhash802
6a69ea2ce3fea0ebfd7a32a1dfc4251bd4d7d8a4fbd44aaa47b82290d0414a9fhash802
6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635ahash802
d78f64551d1b31a31e5998e442f0debd458e011e05019b3951d9ddde997f8384hash802
1d699a46339626db299548e32ed3a77eec267840c3de39b49caf38b88aeb150dsha256801
2d8e5a2763f9a899fda44390d5b8495836c11fb266a61868d52d1f397c5243eesha256801
3e17ce0b30b9fd6863b341ae58ee118dc13f2ee7f1c92ac4b81c04d54480d0e0sha256801
4991873515d6dea70d7769cf67ccd8ea69184e5e454a6e6d1e093b6a3c48eb47sha256801
5a23ca644cb1f310be1abd5f6c6a3b3e15681ced99b0947a7f3465a79aae5089sha256801
a8acc24bb3e6a1a3b66a31ceaefda07d4a0e17415468683458b499f2ba240450sha256801
d55ce447e249ef9045750865fa196c8ca8434c8c484f861b7bdecbceeab7c16esha256801
848036661c71b80ee41566918faa5eae3bf4f03ae807bb4af42cb483b6c141e2sha256801

Showing the top 30 by severity of 449.