UAC Bypass Using Iscsicpl - ImageLoad — Detection Rule

Detects the "iscsicpl.exe" UAC bypass technique that leverages a DLL Search Order hijacking technique to load a custom DLL's from temp or a any user controlled location in the users %PATH%

Read the full analysis on IntelFusions