iscsicpl.exe

type: OSBinaries
Microsoft iSCSI Initiator Control Panel tool

Full path

c:\windows\system32\iscsicpl.exe
c:\windows\syswow64\iscsicpl.exe

Commands

  1. UAC BypassUser T1548.002

    Execute a custom DLL via a trusted high-integrity process without a UAC prompt.

    c:\windows\syswow64\iscsicpl.exe

    c:\windows\syswow64\iscsicpl.exe has a DLL injection through C:\Users\<username>\AppData\Local\Microsoft\WindowsApps\ISCSIEXE.dll, resulting in UAC bypass.

    os: Windows 10, Windows 11

    Execute: DLL

  2. UAC BypassUser T1548.002

    Execute a binary or script as a high-integrity process without a UAC prompt.

    iscsicpl.exe

    Both c:\windows\system32\iscsicpl.exe and c:\windows\system64\iscsicpl.exe have UAC bypass through launching iscicpl.exe, then navigating into the Configuration tab, clicking Report, then launching your custom command.

    os: Windows 10, Windows 11

    Execute: CMDApplication: GUI

Detection

Resources

acknowledgement: hacker.house, Ekitji @eki_erk