UACME

Defeating Windows User Account Control (by hfiref0x)

UACME Alternatives

Similar projects and alternatives to UACME

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a better UACME alternative or higher similarity.

UACME reviews and mentions

Posts with mentions or reviews of UACME. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-01-14.
  • Still being prompted for UAC despite autoElevate being true
    1 project | /r/hacking | 12 Jul 2023
  • Steam Showing "Purchase" Instead of "Play" for a Family Share Game
    1 project | /r/Steam | 11 Jul 2023
    Malware can get admin rights without being run as admin. If you're running a default windows installation, you're very likely already an admin which is much more "dangerous" because of Auto-Elevate and multiple ways you can bypass UAC
  • How to compile newest version of UACME?
    1 project | /r/hacking | 21 Jun 2023
    I am having problems compiling the newest version of UACME tool. (https://github.com/hfiref0x/UACME) I have no clue which step I am missing, but my akagi.exe is simply not working in any of the modes. :( Could someone please provide step by step support?
  • [HELP] Can you point me to a good resource for UAC Bypass technique ?
    4 projects | /r/oscp | 14 Jan 2023
    Hi, I had this issue where I had a lot of problems with UAC Bypass until I found UACME (https://github.com/hfiref0x/UACME). This is the best tool for UAC Bypass. Also, you can use Metasploit, but if you are preparing for OSCP, you should look for a way to bypass UAC without Metasploit. Hope it helps.
  • Linux developers patch security holes faster than anyone else, says Google
    2 projects | news.ycombinator.com | 20 Feb 2022
    There's some very good points in there, but (4) is unfair. It's true that there's no boundary between a sudoer and root in Linux, but there's also no boundary between an Administrator and SYSTEM in Windows. UAC, even in the "secure" AlwaysNotify mode which uses the secure desktop, has countless unpatched bypasses[1].

    Also, (3) should raise some eyebrows for readers paying attention. Cool, Microsoft removed font parsing from the kernel, how wise of them. Wait a second, why was font parsing in the kernel to begin with? With win32k.sys, it shouldn't be surprising that Microsoft has to do more legwork to bring the attack surface back down to the level of other OSes. They're also exploring the use of eBPF in the Windows kernel too[2].

    [1]: https://github.com/hfiref0x/UACME

  • Script or method to Bypass Windows 10 Login
    1 project | /r/hacking | 28 Dec 2021
    Look into UACME a short summary of the general theme of bypasse's can be found here:
  • We were backstabbed when we needed it most
    2 projects | /r/pcmasterrace | 15 Dec 2021
    The usefulness and security offered by UAC is debatable, but it's better to have it so that you can make the decision whether you want to permit the access or not when prompted. There are, of course, numerous ways to bypass UAC silently but to their credit Microsoft is making UAC more and more like a seamless sudo as time goes on.
  • How do you manage users with admin rights?
    2 projects | /r/sysadmin | 18 Nov 2021
    The UACME project has a tool with 70 distinct bypasses for UAC available. These bypasses are well known and documented.
  • Running MSI Afternurner (and other tools) without UAC prompt
    1 project | /r/overclocking | 19 Aug 2021
    Unfortunately I now have to add some more context, because if I don't a bunch of other InfoSec peeps are going to come here and do some chest beating. So, let's do that: UAC is nowhere near foolproof and most malware authors write malware specifically to exploit the known methods of avoiding the prompt. However, as most of you home PC owners are going to be administrators, turning off the UAC prompt completely makes no sense. So, whilst not-that-good, UAC may one day pop a Yes/No prompt where you click NO and save yourself a lot of heartache.
  • hfiref0x/UACME - Defeating Windows User Account Control
    1 project | /r/GithubSecurityTools | 18 Aug 2021
  • A note from our sponsor - InfluxDB
    www.influxdata.com | 29 Apr 2024
    Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality. Learn more →

Stats

Basic UACME repo stats
11
5,918
4.8
13 days ago

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com