TACTIC: PRIVILEGE ESCALATION
Bypass User Account Control (T1548.002): real cases
MITRE Definition ↗ Adversaries bypass Windows UAC mechanisms to elevate process execution rights.
Key Facts
Technique ID
T1548.002
Privilege Escalation
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
- ATT&CK Technique Identifier: T1548.002.
- Tactical Phase: Privilege Escalation.
- Substantiated in 1 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Vachon-Desjardins (Netwalker Ransomware)
sentenced 2020-12-16
Primary Source Evidence Excerpt: Indictment ¶ 11, Page 6
"The attacker used CMSTP and eventvwr.exe registry hijack methods to bypass Windows User Account Control without user prompting."
U.S. District Court for the Middle District of Florida
View full case dossier →