Suspicious UAC Bypass via control.exe App Paths or Shell Open Command Hijack

PremiumReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-10-05
Updated
2026-10-05

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects registry modifications that hijack the control.exe App Paths key or an AppX shell open command handler, techniques used to bypass User Account Control by redirecting an auto-elevated process to attacker-controlled code. Adversaries plant these keys so a trusted elevated binary launches their payload without a UAC prompt. Such registry writes outside of software installation are highly suspicious.

Related detections9 linkedT1548.002 — drag to rearrange
Malicious UAC Disable via EnableLUA Registry Modification via registry_set
Suspicious Remote UAC Restriction Disabled via LocalAccountTokenFilterPolicy (via process_creation)
Suspicious LocalAccountTokenFilterPolicy Registry Modification
Windows Registry and PowerShell Modification of ms-settings Protocol Handler
Suspicious Remote Desktop Enablement via Registry By Ransomware
Suspicious VBScript Payload Stored in CurrentVersion Registry Value (via registry_set)
Malicious UAC Bypass via COMAutoApprovalList Registry Modification (via registry_set)
Suspicious UAC Bypass via COMAutoApprovalList Registry Modification (via registry_set)
Malicious UAC Bypass via explorer.exe NOUACCHECK Argument
Suspicious UAC Bypass via control.exe App Paths or Shell Open Command Hijack
Pivot detection · T1548.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.