UAC Bypass Using NTFS Reparse Point - File — Detection Rule

Detects the pattern of UAC Bypass using NTFS reparse point and wusa.exe DLL hijacking (UACMe 36)

Read the full analysis on IntelFusions