← Back to SOC feed Coverage →

UAC Bypass Abusing Winsat Path Parsing - File

sigma HIGH SigmaHQ
T1548.002
imFileEvent
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at SigmaHQ →
Retrieved: 2026-03-25T03:05:59Z · Confidence: medium

Hunt Hypothesis

Adversaries may bypass UAC by exploiting a path parsing vulnerability in winsat.exe to execute payloads with elevated privileges. SOC teams should proactively hunt for this behavior in Azure Sentinel to identify potential UAC bypass attempts and mitigate lateral movement or persistence risks.

Detection Rule

Sigma (Original)

title: UAC Bypass Abusing Winsat Path Parsing - File
id: 155dbf56-e0a4-4dd0-8905-8a98705045e8
status: test
description: Detects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)
references:
    - https://github.com/hfiref0x/UACME
author: Christian Burkard (Nextron Systems)
date: 2021-08-30
modified: 2022-10-09
tags:
    - attack.defense-evasion
    - attack.privilege-escalation
    - attack.t1548.002
logsource:
    category: file_event
    product: windows
detection:
    selection:
        TargetFilename|startswith: 'C:\Users\'
        TargetFilename|endswith:
            - '\AppData\Local\Temp\system32\winsat.exe'
            - '\AppData\Local\Temp\system32\winmm.dll'
    condition: selection
falsepositives:
    - Unknown
level: high

KQL (Azure Sentinel)

imFileEvent
| where TargetFileName startswith "C:\\Users\\" and (TargetFileName endswith "\\AppData\\Local\\Temp\\system32\\winsat.exe" or TargetFileName endswith "\\AppData\\Local\\Temp\\system32\\winmm.dll")

False Positive Guidance

MITRE ATT&CK Context

Original source: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_uac_bypass_winsat.yml