UAC Bypass via COM Elevation Moniker into ServiceModelReg.exe
Detects the execution of ServiceModelReg.exe following parent process activity involving vsdbg.dll/vsdbg.exe, coupled with cross-process access indicators consistent with COM Elevation Moniker UAC bypass and potential process hollowing. This pattern is associated with the PUROSANGUE loader chain used to execute malicious code within a high-integrity process context.
Splunk (SPL)

