iscsicpl.exe
Microsoft iSCSI Initiator Control Panel tool
Full path
c:\windows\system32\iscsicpl.exe
c:\windows\syswow64\iscsicpl.exeCommands
Execute a custom DLL via a trusted high-integrity process without a UAC prompt.
c:\windows\syswow64\iscsicpl.exec:\windows\syswow64\iscsicpl.exe has a DLL injection through
C:\Users\<username>\AppData\Local\Microsoft\WindowsApps\ISCSIEXE.dll, resulting in UAC bypass.os: Windows 10, Windows 11
Execute a binary or script as a high-integrity process without a UAC prompt.
iscsicpl.exeBoth
c:\windows\system32\iscsicpl.exeandc:\windows\system64\iscsicpl.exehave UAC bypass through launching iscicpl.exe, then navigating into the Configuration tab, clicking Report, then launching your custom command.os: Windows 10, Windows 11
Detection
- Sigma https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_uac_bypass_iscsicpl.yml
- IOCC:\Users\<username>\AppData\Local\Microsoft\WindowsApps\ISCSIEXE.dll
- IOCSuspicious child process to iscsicpl.exe like cmd, powershell etc.
Resources
acknowledgement: hacker.house, Ekitji @eki_erk