UAC bypass via RequestTrace scheduled task hijack

Identifies attempts to bypass User Account Control (UAC) by abusing the RequestTrace scheduled task, a lesser-known but powerful auto-elevated Windows mechanism that can be repurposed by attackers to gain administrative-level execution without user consent. RequestTrace scheduled task can be started by pressing SHIFT+CTRL+WIN+T opening a stealthy attack vector for adversaries.

Back to all rules