T1548.002: Bypass User Account Control
Adversaries may bypass UAC mechanisms to elevate process privileges on Windows systems.
Total Capable Binaries: 6
•
Windows: 6
•
Linux: 0
•
macOS: 0
Living-off-the-Land Matrix for T1548.002
Across 6 verified binariesWindows1 payloads
ComputerDefaults.exe
ComputerDefaults.exe is a Windows system utility for managing default applications for tasks like web browsing, emailing, and media playback.
Sample Attack Vector:
ComputerDefaults.exeWindows1 payloads
Eudcedit.exe
Private Character Editor Windows Utility
Sample Attack Vector:
eudceditWindows2 payloads
Eventvwr.exe
Displays Windows Event Logs in a GUI window.
Sample Attack Vector:
eventvwr.exeWindows2 payloads
iscsicpl.exe
Microsoft iSCSI Initiator Control Panel tool
Sample Attack Vector:
c:\windows\syswow64\iscsicpl.exeWindows1 payloads
odbcad32.exe
ODBC Data Source Administrator to manage User/System DSNs and ODBC drivers.
Sample Attack Vector:
odbcad32.exeWindows1 payloads
Wsreset.exe
Used to reset Windows Store settings according to its manifest file
Sample Attack Vector:
wsreset.exeCurated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point