UAC Bypass Using IDiagnostic Profile - File — Detection Rule

Detects the creation of a file by "dllhost.exe" in System32 directory part of "IDiagnosticProfileUAC" UAC bypass technique

Read the full analysis on IntelFusions