Catalog LOLBAS

LOL · Binary

ComputerDefaults.exe

1 technique WindowsLOLBAS GPL-3.0

UAC Bypass

UAC BypassPrivilege Escalation Windows

Upon execution, ComputerDefaults.exe checks two registry values at HKEY_CURRENT_USER\Software\Classes\ms-settings\Shell\open\command; if these are set by an attacker, the set command will be executed as a high-integrity process without a UAC prompt being displayed to the user. See 'resources' for which registry keys/values to set.

Use Execute a binary or script as a high-integrity process without a UAC prompt.

ComputerDefaults.exe
Context
user
Native
UAC Bypass
Detection
IOC: Event ID 10
IOC: A binary or script spawned as a child process of ComputerDefaults.exe
IOC: Changes to HKEY_CURRENT_USER\Software\Classes\ms-settings\Shell\open\command