MITRE ATT&CK T1548 Detection Rules | Fibratus
Fibratus detection rules mapped to MITRE ATT&CK technique T1548. Kernel-level, behavior-driven detection coverage.
Rules in this category
- Potential privilege escalation via elevated IFileOperation COM interface
- UAC bypass via assembly Native Image Cache hijack
- UAC bypass via CDSSync scheduled task hijack
- UAC bypass via command handler hijacking
- UAC bypass via Control Panel applet execution hijack
- UAC bypass via DiskCleanup scheduled task hijack
- UAC bypass via DLL hijack from Windows Media player directory
- UAC bypass via .NET Code Profiler DLL Hijack
- UAC bypass via elevated Internet Explorer add-on installer COM interface
- UAC bypass via ICMLuaUtil COM interface
- UAC bypass via NTFS junction DLL hijacking
- UAC bypass via Program Compatibility Assistant scheduled task hijack
- UAC bypass via RequestTrace scheduled task hijack
- UAC bypass via rouge MMC snap-in
- UAC bypass via trusted Windows directory masquerading