Suspicious LocalAccountTokenFilterPolicy Registry Modification

PremiumReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-06-13
Updated
2026-08-28

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects modification of the LocalAccountTokenFilterPolicy value, which disables remote UAC filtering so local admin accounts retain full privileges over the network. Play ransomware operators set this to ease lateral movement.

Related detections9 linkedT1112 — drag to rearrange
Suspicious Remote UAC Restriction Disabled via LocalAccountTokenFilterPolicy (via process_creation)
Windows Registry and PowerShell Modification of ms-settings Protocol Handler
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Malicious Gh0stBins RAT Registry Marker HHClient
Suspicious Banana RAT UAC Skip Environment Variable in PowerShell
Suspicious PebbleDash C2 Configuration Stored Under WMI Security Key (via registry_set)
Suspicious WDigest UseLogonCredential Enablement for Plaintext Credential Theft (via registry_set)
PowerShell Storing an Encoded Payload in the Registry (via process_creation)
Malicious UAC Bypass via sdclt Handler Hijack (via registry_set)
Suspicious LocalAccountTokenFilterPolicy Registry Modification
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.