UAC Bypass Using Disk Cleanup — Detection Rule

Detects the pattern of UAC Bypass using scheduled tasks and variable expansion of cleanmgr.exe (UACMe 34)

Read the full analysis on IntelFusions