Windows CMSTP UAC Bypass Attempt via Autoelevate COM Object DllHost Execution

Detects DllHost.exe spawning CMSTP-related autoelevate COM objects by matching known Processid values and high/system integrity.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nik Seetharaman, Christian Burkard (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-07-31
Updated
2026-07-30
title: Windows CMSTP UAC Bypass Attempt via Autoelevate COM Object DllHost Execution
id: 67f575f2-fb8f-440c-b039-afffbd34f608
status: stable
description: This rule flags process creation events where the parent process is DllHost.exe with command lines that include specific COM Processid values tied to CMSTP-enabled autoelevate COM objects. UAC bypass techniques matter because they aim to obtain elevated execution without prompting the user. The detection relies on process creation telemetry, focusing on the parent image and parent command-line content plus high/system integrity levels.
references:
  - https://web.archive.org/web/20190720093911/http://www.endurant.io/cmstp/detecting-cmstp-enabled-code-execution-and-uac-bypass-with-sysmon/
  - https://twitter.com/hFireF0X/status/897640081053364225
  - https://medium.com/falconforce/falconfriday-detecting-uac-bypasses-0xff16-86c2a9107abf
  - https://github.com/hfiref0x/UACME
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp_com_object_access.yml
author: Nik Seetharaman, Christian Burkard (Nextron Systems), Huntrule Team
date: 2019-07-31
modified: 2024-12-01
tags:
  - attack.execution
  - attack.privilege-escalation
  - attack.stealth
  - attack.t1548.002
  - attack.t1218.003
  - attack.g0069
  - car.2019-04-001
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|endswith: \DllHost.exe
    ParentCommandLine|contains:
      - " /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}"
      - " /Processid:{3E000D72-A845-4CD9-BD83-80C07C3B881F}"
      - " /Processid:{BD54C901-076B-434E-B6C7-17C531F4AB41}"
      - " /Processid:{D2E7041B-2927-42FB-8E9F-7CE93B6DC937}"
      - " /Processid:{E9495B87-D950-4AB5-87A5-FF6D70BF3E90}"
    IntegrityLevel:
      - High
      - System
      - S-1-16-16384
      - S-1-16-12288
  condition: selection
falsepositives:
  - Legitimate CMSTP use (unlikely in modern enterprise environments)
level: high
license: DRL-1.1
related:
  - id: 4b60e6f2-bf39-47b4-b4ea-398e33cfe253
    type: derived