Techniques
Sample rules
Use of VisualUiaVerifyNative.exe
- source: sigma
- technicques:
- t1218
Description
VisualUiaVerifyNative.exe is a Windows SDK that can be used for AWL bypass and is listed in Microsoft’s recommended block rules.
Detection logic
condition: selection
selection:
- Image|endswith: \VisualUiaVerifyNative.exe
- OriginalFileName: VisualUiaVerifyNative.exe