INTEL_REPORT
Google Project Zero · published 2/11/2026, 11:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Bypassing Administrator Protection by Abusing UI Access In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didn’t exist. I described one of the ways I was able to bypass the feature before it was released. In total I found 9 bypasses during my research that have now all been fixed. In this blog post I wanted to describe the root cause of 5 of those 9 issues, specifically the imple…
https://projectzero.google/2026/02/windows-administrator-protection.html
sha256:41cfd05b5083cf59169484dfca5d96d9d1f88773eb82afc0b218487d580b8777
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.