CMSTP UAC Bypass via COM Object Access — Detection Rule

Detects UAC Bypass Attempt Using Microsoft Connection Manager Profile Installer Autoelevate-capable COM Objects (e.g. UACMe ID of 41, 43, 58 or 65)

Read the full analysis on IntelFusions