Skip to content

Hide Navigation Hide TOC

UAC Bypass Using Iscsicpl - ImageLoad (9ed5959a-c43c-4c59-84e3-d28628429456)

Detects the "iscsicpl.exe" UAC bypass technique that leverages a DLL Search Order hijacking technique to load a custom DLL's from temp or a any user controlled location in the users %PATH%

Cluster A Galaxy A Cluster B Galaxy B Level
Bypass User Account Control - T1548.002 (120d5519-3098-4e1c-9191-2aa61232f073) Attack Pattern UAC Bypass Using Iscsicpl - ImageLoad (9ed5959a-c43c-4c59-84e3-d28628429456) Sigma-Rules 1
Bypass User Account Control - T1548.002 (120d5519-3098-4e1c-9191-2aa61232f073) Attack Pattern Abuse Elevation Control Mechanism - T1548 (67720091-eee3-4d2d-ae16-8264567f6f5b) Attack Pattern 2