Rule Info
Name
UAC Bypass Using Event Viewer RecentViews
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects the pattern of UAC Bypass using Event Viewer RecentViews
Date
2022-11-22 00:00:00
Modified
None
Id
30fc8de7-d833-40c4-96b6-28319fbc4f6c
Tags
attack.privilege-escalation attack.stealth
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #5966 from @nasbench - Update mitre tags to use attack v19
2026-04-29
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
