Regedit as Trusted Installer (883835a7-df45-43e4-bf1d-4268768afda4)
Detects a regedit started with TrustedInstaller privileges or by ProcessHacker.exe
| Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
|---|---|---|---|---|
| Regedit as Trusted Installer (883835a7-df45-43e4-bf1d-4268768afda4) | Sigma-Rules | Abuse Elevation Control Mechanism - T1548 (67720091-eee3-4d2d-ae16-8264567f6f5b) | Attack Pattern | 1 |