UAC bypass via DiskCleanup scheduled task hijack
Detects attempts to bypass User Account Control (UAC) by abusing the built-in Windows Disk Cleanup scheduled task as a privilege escalation vector. Adversaries commonly abuse trusted, auto-elevated Windows components to evade UAC prompts and silently obtain high-integrity execution without requiring explicit user consent.
- Plataforma: Windows
- Severidad: High
- Táctica MITRE: Escalada de privilegios
- Técnicas MITRE: T1548, T1548.002