UAC bypass via RequestTrace scheduled task hijack
Identifies attempts to bypass User Account Control (UAC) by abusing the RequestTrace scheduled task, a lesser-known but powerful auto-elevated Windows mechanism that can be repurposed by attackers to gain administrative-level execution without user consent. RequestTrace scheduled task can be started by pressing SHIFT+CTRL+WIN+T opening a stealthy attack vector for adversaries.
- Platform: Windows
- Severity: High
- MITRE Tactic: Privilege Escalation
- MITRE Techniques: T1548, T1548.002