LoFP LoFP / legitimate testing of microsoft ui parts.

Techniques

Sample rules

Use of VisualUiaVerifyNative.exe

Description

VisualUiaVerifyNative.exe is a Windows SDK that can be used for AWL bypass and is listed in Microsoft’s recommended block rules.

Detection logic

condition: selection
selection:
- Image|endswith: \VisualUiaVerifyNative.exe
- OriginalFileName: VisualUiaVerifyNative.exe