T1548.002Tactic: Privilege EscalationOfficial MITRE ATT&CK Page

T1548.002: Bypass User Account Control

Adversaries may bypass UAC mechanisms to elevate process privileges on Windows systems.

Total Capable Binaries: 6
Windows: 6
Linux: 0
macOS: 0

Living-off-the-Land Matrix for T1548.002

Across 6 verified binaries
Windows1 payloads

ComputerDefaults.exe

ComputerDefaults.exe is a Windows system utility for managing default applications for tasks like web browsing, emailing, and media playback.

Sample Attack Vector:
ComputerDefaults.exe
Windows1 payloads

Eudcedit.exe

Private Character Editor Windows Utility

Sample Attack Vector:
eudcedit
Windows2 payloads

Eventvwr.exe

Displays Windows Event Logs in a GUI window.

Sample Attack Vector:
eventvwr.exe
Windows2 payloads

iscsicpl.exe

Microsoft iSCSI Initiator Control Panel tool

Sample Attack Vector:
c:\windows\syswow64\iscsicpl.exe
Windows1 payloads

odbcad32.exe

ODBC Data Source Administrator to manage User/System DSNs and ODBC drivers.

Sample Attack Vector:
odbcad32.exe
Windows1 payloads

Wsreset.exe

Used to reset Windows Store settings according to its manifest file

Sample Attack Vector:
wsreset.exe
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point