Windows UAC Bypass via Event Viewer RecentViews Path in Process Command Line

Flags Windows processes whose command lines reference Event Viewer RecentViews and use redirection, consistent with UAC bypass techniques.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-11-22
Updated
2026-07-30

What it detects

This rule flags Windows process creation where the command line includes paths referencing Event Viewer RecentViews, including the abbreviated RecentViews directory. It also matches command-line redirection characters, which commonly indicate data being copied or written to the RecentViews location to trigger elevated behavior. The detection relies on process creation telemetry, specifically the full command line content captured at execution time.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.