UAC Bypass Using Consent and Comctl32 - File — Detection Rule

Detects the pattern of UAC Bypass using consent.exe and comctl32.dll (UACMe 22)

Read the full analysis on IntelFusions