Potential privilege escalation via elevated IFileOperation COM interface

Identifies potential privilege escalation attempts through abuse of the elevated IFileOperation COM interface to bypass User Account Control (UAC) and gain unauthorized administrative privileges. Adversaries leverage trusted Windows components and auto-elevated COM objects to perform file operations in protected system locations.

Back to all rules