Suspicious Remote UAC Restriction Disabled via LocalAccountTokenFilterPolicy (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-07-12
Updated
2026-08-28

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects a reg add command setting LocalAccountTokenFilterPolicy to 1, which disables remote UAC token filtering and grants full administrative access over the network to local accounts. Akira ransomware operators set this value to enable lateral movement with local administrator credentials.

Related detections9 linkedT1112 — drag to rearrange
Suspicious LocalAccountTokenFilterPolicy Registry Modification
Windows Registry and PowerShell Modification of ms-settings Protocol Handler
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Malicious Gh0stBins RAT Registry Marker HHClient
Suspicious Banana RAT UAC Skip Environment Variable in PowerShell
Suspicious PebbleDash C2 Configuration Stored Under WMI Security Key (via registry_set)
Suspicious WDigest UseLogonCredential Enablement for Plaintext Credential Theft (via registry_set)
PowerShell Storing an Encoded Payload in the Registry (via process_creation)
Malicious UAC Bypass via sdclt Handler Hijack (via registry_set)
Suspicious Remote UAC Restriction Disabled via LocalAccountTokenFilterPolicy (via process_creation)
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.