UAC Bypass With Fake DLL — Detection Rule

Attempts to load dismcore.dll after dropping it

Read the full analysis on IntelFusions