UAC Disabled — Detection Rule

Detects when an attacker tries to disable User Account Control (UAC) by setting the registry value "EnableLUA" to 0.

Read the full analysis on IntelFusions