ceramicskate0 / SWELF

Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.
https://ceramicskate0.github.io/SWELF/
GNU Affero General Public License v3.0
24 stars 7 forks source link

Add DelegateExecute reg value for UAC bypasses #121

Closed ceramicskate0 closed 4 years ago

ceramicskate0 commented 4 years ago

https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1088/T1088.md#atomic-test-3---bypass-uac-using-fodhelper

ceramicskate0 commented 4 years ago

added in push 138384f