UAC Notification Disabled

Rule Info

Name
UAC Notification Disabled
Author
frack113, Nasreddine Bencherchali (Nextron Systems)
Description
Detects when an attacker tries to disable User Account Control (UAC) notification by tampering with the "UACDisableNotify" value. UAC is a critical security feature in Windows that prevents unauthorized changes to the operating system. It prompts the user for permission or an administrator password before allowing actions that could affect the system's operation or change settings that affect other users. When "UACDisableNotify" is set to 1, UAC prompts are suppressed.
Date
2024-05-10 00:00:00
Modified
None
Id
c5f6a85d-b647-40f7-bbad-c10b66bab038
Tags
attack.privilege_escalation attack.defense_evasion attack.t1548.002 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
frack113
Merge PR #4844 from @frack113 - Update UAC based rules
2024-05-10