UAC Bypass via eventviewer.exe
Detects attempts to bypass User Account Control (UAC) by abusing 'eventviewer.exe'. This rule specifically looks for 'eventviewer.exe' being initiated by suspicious processes like 'powershell.exe', 'cmd.exe', 'rundll32.exe', or 'Optimax.dll', while excluding legitimate command-line usage of 'eventvwr.exe'.
Microsoft Sentinel (KQL)

