UAC bypass via command handler hijacking

Detects attempts to bypass User Account Control (UAC) by hijacking command handler registry keys associated with auto-elevated system components. Attackers abuse this technique to redirect execution flow and spawn elevated processes without user consent.

Back to all rules