[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxAZRHUhUM_vQ_1vugkprdbvZrtJwIGbaoKKs0KKdgvk":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1042,"What is the key principle behind using sdclt.exe to bypass UAC in Windows 10?","The technique exploits the fact that sdclt.exe runs with elevated privileges because its manifest specifies `requireAdministrator`. During startup, sdclt.exe searches the registry under `HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe` and can be hijacked by creating that key with a malicious executable as the default value. This allows an attacker to launch a payload with high integrity without triggering a UAC prompt. For more details, see the [Study Notes of using sdclt.exe to bypass UAC](\u002Fnews\u002Fstudy-notes-of-using-sdclt-exe-to-bypass-uac).","\u003Cp>The technique exploits the fact that sdclt.exe runs with elevated privileges because its manifest specifies `requireAdministrator`. During startup, sdclt.exe searches the registry under `HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe` and can be hijacked by creating that key with a malicious executable as the default value. This allows an attacker to launch a payload with high integrity without triggering a UAC prompt. For more details, see the [Study Notes of using sdclt.exe to bypass UAC](\u002Fnews\u002Fstudy-notes-of-using-sdclt-exe-to-bypass-uac).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fstudy-notes-of-using-sdclt-exe-to-bypass-uac\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-key-principle-behind-using-sdcltexe-to-bypass-uac-in-windows-10-1777480773540","UAC bypass, sdclt.exe, registry hijacking, Windows 10, App Paths, HKCU",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},255,"Study Notes of using sdclt.exe to bypass UAC","study-notes-of-using-sdclt-exe-to-bypass-uac","Learn how sdclt.exe bypasses UAC in Windows 10 via registry modification, with testing insights and defensive strategies to detect and prevent attacks.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Matt Nelson‏ @enigma0x3 recently published an article revealing a technique to bypass Win10 UAC by modifying registry key values under HKCU. The article links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2017\u002F03\u002F14\u002Fbypassing-uac-using-app-paths\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2017\u002F03\u002F17\u002Ffileless-uac-bypass-using-sdclt-exe\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will test it, share testing insights, and organize offensive and defensive techniques for this method.\u003C\u002Fp>\u003Ch2>0x02 Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Sigcheck\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Can be used to view the manifest of exe files.\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fbb897441.aspx\u003C\u002Fp>\u003Cp>In the Win10 environment, run in cmd:\u003C\u002Fp>\u003Cp>sigcheck.exe -m c:\\windows\\system32\\sdclt.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015589554_0_1c121b3fe3.jpeg\">\u003C\u002Fp>\u003Cp>level=\"requireAdministrator\"\u003C\u002Fp>\u003Cp>true indicates that privileges can be automatically elevated\u003C\u002Fp>\u003Cp>In the Win7 environment, also use Sigcheck to view sdclt.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015595460_1_c4838df987.jpeg\">\u003C\u002Fp>\u003Cp>level=\"asInvoker\" indicates that privileges will not be elevated, which is why Win7 is not supported\u003C\u002Fp>\u003Cp>Next, use ProcessMonitor to monitor the startup process of sdclt.exe and check if it calls other programs\u003C\u002Fp>\u003Ch2>0x03 Actual Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test environment: Win 10 x64\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was only tested successfully on Windows 10\u003C\u002Fp>\u003Cp>Enter in cmd:\u003C\u002Fp>\u003Cp>sdclt.exe\u003C\u002Fp>\u003Cp>Normal startup, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015598444_2_0a0b12061e.jpeg\">\u003C\u002Fp>\u003Cp>Use ProcessMonitor to view the startup process\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015601221_3_9ddc495f71.jpeg\">\u003C\u002Fp>\u003Cp>During the startup of sdclt.exe, it searches for the registry key HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe with High privileges\u003C\u002Fp>\u003Cp>If the registry key is manually modified and parameters are filled in, UAC bypass can be achieved\u003C\u002Fp>\u003Cp>\u003Cstrong>The bypass method is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Create a new registry key:\u003C\u002Fp>\u003Cp>HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe\u003C\u002Fp>\u003Cp>And set the default value to cmd.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015604272_4_0b9f5e37a2.jpeg\">\u003C\u002Fp>\u003Cp>Restart sdclt.exe and observe that it proceeds to execute cmd.exe, successfully bypassing UAC, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015606690_5_d942e74a59.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The launched exe cannot include parameters, otherwise it will fail\u003C\u002Fp>\u003Cp>For example, entering C:\\Windows\\System32\\cmd.exe \u002Fc calc.exe will not achieve exploitation\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015608687_6_a9befd59d7.jpeg\">\u003C\u002Fp>\u003Cp>In practical exploitation, if parameters need to be added, one can first write the parameters into a script and then load the script for exploitation\u003C\u002Fp>\u003Cp>For better stealth and to achieve 'fileless' exploitation, try to find if sdclt.exe supports commands that accept parameters\u003C\u002Fp>\u003Cp>Matt Nelson‏ @enigma0x3's second article addresses this issue, the article link is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2017\u002F03\u002F17\u002Ffileless-uac-bypass-using-sdclt-exe\u002F\u003C\u002Fp>\u003Cp>Modify the registry to hijack the parameters passed to \u002Fkickoffelev, achieving 'fileless' exploitation\u003C\u002Fp>\u003Cp>\u003Cstrong>The specific method is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Create a new registry key value:\u003C\u002Fp>\u003Cp>HKCU:\\Software\\Classes\\exefile\\shell\\runas\\command\\\u003C\u002Fp>\u003Cp>Create a new key named isolatedCommand of type REG_SZ, with content as startup parameters, which can be set to notepad.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015611385_7_54f34c4352.jpeg\">\u003C\u002Fp>\u003Cp>Then enter in cmd:\u003C\u002Fp>\u003Cp>sdclt.exe \u002FKickOffElev\u003C\u002Fp>\u003Cp>Successfully executed the parameter, launching notepad.exe, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015613502_8_db8a85b99c.jpeg\">\u003C\u002Fp>\u003Cp>Replace the parameter with regedit.exe, the launch process is not intercepted by UAC, successfully bypassed\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015615178_9_406ae41db0.jpeg\">\u003C\u002Fp>\u003Cp>However, creating the registry key exefile\\shell\\runas\\command\\ will affect the launch of other normal exe programs, so in exploitation, it is necessary to first create the key, execute sdclt.exe, and then delete the key\u003C\u002Fp>\u003Cp>The entire process is implemented via PowerShell, the complete POC can be referred to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fenigma0x3\u002FMisc-PowerShell-Stuff\u002Fblob\u002Fmaster\u002FInvoke-SDCLTBypass.ps1\u003C\u002Fp>\u003Ch2>0x04 Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Defense:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If UAC permissions are set to 'Always Notify', this method will fail\u003C\u002Fp>\u003Cp>\u003Cstrong>Detection:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Monitor registry key values:\u003C\u002Fp>\u003Cp>HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe\u003C\u002Fp>\u003Cp>HKCU:\\Software\\Classes\\exefile\\shell\\runas\\command\\\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Matt Nelson‏ @enigma0x3 recently published an article revealing a technique to bypass Win10 UAC by modifying registry key values under HKCU. The article links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2017\u002F03\u002F14\u002Fbypassing-uac-using-app-paths\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2017\u002F03\u002F17\u002Ffileless-uac-bypass-using-sdclt-exe\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will test it, share testing insights, and organize offensive and defensive techniques for this method.\u003C\u002Fp>\u003Ch2>0x02 Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Sigcheck\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Can be used to view the manifest of exe files.\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fbb897441.aspx\u003C\u002Fp>\u003Cp>In the Win10 environment, run in cmd:\u003C\u002Fp>\u003Cp>sigcheck.exe -m c:\\windows\\system32\\sdclt.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015589554_0_1c121b3fe3-1.jpeg\">\u003C\u002Fp>\u003Cp>level=\"requireAdministrator\"\u003C\u002Fp>\u003Cp>true indicates that privileges can be automatically elevated\u003C\u002Fp>\u003Cp>In the Win7 environment, also use Sigcheck to view sdclt.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015595460_1_c4838df987-1.jpeg\">\u003C\u002Fp>\u003Cp>level=\"asInvoker\" indicates that privileges will not be elevated, which is why Win7 is not supported\u003C\u002Fp>\u003Cp>Next, use ProcessMonitor to monitor the startup process of sdclt.exe and check if it calls other programs\u003C\u002Fp>\u003Ch2>0x03 Actual Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test environment: Win 10 x64\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was only tested successfully on Windows 10\u003C\u002Fp>\u003Cp>Enter in cmd:\u003C\u002Fp>\u003Cp>sdclt.exe\u003C\u002Fp>\u003Cp>Normal startup, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015598444_2_0a0b12061e-1.jpeg\">\u003C\u002Fp>\u003Cp>Use ProcessMonitor to view the startup process\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015601221_3_9ddc495f71-1.jpeg\">\u003C\u002Fp>\u003Cp>During the startup of sdclt.exe, it searches for the registry key HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe with High privileges\u003C\u002Fp>\u003Cp>If the registry key is manually modified and parameters are filled in, UAC bypass can be achieved\u003C\u002Fp>\u003Cp>\u003Cstrong>The bypass method is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Create a new registry key:\u003C\u002Fp>\u003Cp>HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe\u003C\u002Fp>\u003Cp>And set the default value to cmd.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015604272_4_0b9f5e37a2-1.jpeg\">\u003C\u002Fp>\u003Cp>Restart sdclt.exe and observe that it proceeds to execute cmd.exe, successfully bypassing UAC, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015606690_5_d942e74a59-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The launched exe cannot include parameters, otherwise it will fail\u003C\u002Fp>\u003Cp>For example, entering C:\\Windows\\System32\\cmd.exe \u002Fc calc.exe will not achieve exploitation\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015608687_6_a9befd59d7-1.jpeg\">\u003C\u002Fp>\u003Cp>In practical exploitation, if parameters need to be added, one can first write the parameters into a script and then load the script for exploitation\u003C\u002Fp>\u003Cp>For better stealth and to achieve 'fileless' exploitation, try to find if sdclt.exe supports commands that accept parameters\u003C\u002Fp>\u003Cp>Matt Nelson‏ @enigma0x3's second article addresses this issue, the article link is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2017\u002F03\u002F17\u002Ffileless-uac-bypass-using-sdclt-exe\u002F\u003C\u002Fp>\u003Cp>Modify the registry to hijack the parameters passed to \u002Fkickoffelev, achieving 'fileless' exploitation\u003C\u002Fp>\u003Cp>\u003Cstrong>The specific method is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Create a new registry key value:\u003C\u002Fp>\u003Cp>HKCU:\\Software\\Classes\\exefile\\shell\\runas\\command\\\u003C\u002Fp>\u003Cp>Create a new key named isolatedCommand of type REG_SZ, with content as startup parameters, which can be set to notepad.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015611385_7_54f34c4352-1.jpeg\">\u003C\u002Fp>\u003Cp>Then enter in cmd:\u003C\u002Fp>\u003Cp>sdclt.exe \u002FKickOffElev\u003C\u002Fp>\u003Cp>Successfully executed the parameter, launching notepad.exe, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015613502_8_db8a85b99c-1.jpeg\">\u003C\u002Fp>\u003Cp>Replace the parameter with regedit.exe, the launch process is not intercepted by UAC, successfully bypassed\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015615178_9_406ae41db0-1.jpeg\">\u003C\u002Fp>\u003Cp>However, creating the registry key exefile\\shell\\runas\\command\\ will affect the launch of other normal exe programs, so in exploitation, it is necessary to first create the key, execute sdclt.exe, and then delete the key\u003C\u002Fp>\u003Cp>The entire process is implemented via PowerShell, the complete POC can be referred to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fenigma0x3\u002FMisc-PowerShell-Stuff\u002Fblob\u002Fmaster\u002FInvoke-SDCLTBypass.ps1\u003C\u002Fp>\u003Ch2>0x04 Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Defense:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If UAC permissions are set to 'Always Notify', this method will fail\u003C\u002Fp>\u003Cp>\u003Cstrong>Detection:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Monitor registry key values:\u003C\u002Fp>\u003Cp>HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe\u003C\u002Fp>\u003Cp>HKCU:\\Software\\Classes\\exefile\\shell\\runas\\command\\\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",350,"Onedaysec",3,"published","2026-02-02T07:25:19.985Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Bypass UAC with sdclt.exe: Testing & Defense Techniques","UAC bypass, sdclt.exe, Windows 10 security, registry hijacking, fileless attack, defense techniques, ProcessMonitor, Sigcheck",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,47,4],1046,1045,1044,1043,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.017Z","2026-07-23T16:02:28.411Z","draft","2026-07-23T16:16:17.527Z"]