AI prompts
base on # TrollUAC
- .NET library that serves as a boilerplate to bypass UAC x64 using uiAccess
- Any* process with the uiAccess flag enabled can "Send Keystrokes" to high integrity processes even from medium integrity
- We steal the token of On Screen Keyboard (uiAccess enabled) to spawn a new process that does GUI automation
- The GUI automation simply sends keystrokes to taskmgr (auto elevate) to spawn our new desired process in high integrity
- *Refer to tiraniddo's article for requirements, although they can easily be conjured up
![TrollUAC](https://github.com/cybersectroll/TrollUAC/assets/169176042/ffe843de-6d92-4508-9046-1cec850473ad)
# Why?
Because I was bored of registry / DLL / com UAC bypasses
# Benefits
The code really serves as boilerplate to abuse the uiAcess feature in convenient c# where you can easily replace the GUI automation code/logic to your liking. Because the library is so simple, you have granular and absolute control over your actions as opposed to other libraries out there. (i.e awareness of what your code is actually doing)
# Credits (rewrite of project)
c# port of https://www.tiraniddo.dev/2019/02/accessing-access-tokens-for-uiaccess.html with some troll flavouring.\
Refer to article for full explanation, technique is 5 years old but still works :)
# Compiling
- Download project & Compile solution as Release, x64, check the box "allow unsafe code"
- No external dependencies needed
# Usage
```
> Start with Medium Integrity
> [System.Reflection.Assembly]::LoadFrom("C:\users\public\TrollUAC.dll") //can Load() as well
> [TrollUAC]::uiAccessPlease(<Process>) //for non sys32 binaries, set full path
> [TrollUAC]::uiAccessPlease("notepad")
```
# OPSEC
- This project is declared 100% opsec unsafe
# Wishlist - Project was done over the weekend and I have no time/intent to pursue the following:
- none, i think it works fine in any non-production environment like security certification exams
# Disclaimer
Should only be used for educational purposes!
", Assign "at most 3 tags" to the expected json: {"id":"10346","tags":[]} "only from the tags list I provide: [{"id":77,"name":"3d"},{"id":89,"name":"agent"},{"id":17,"name":"ai"},{"id":54,"name":"algorithm"},{"id":24,"name":"api"},{"id":44,"name":"authentication"},{"id":3,"name":"aws"},{"id":27,"name":"backend"},{"id":60,"name":"benchmark"},{"id":72,"name":"best-practices"},{"id":39,"name":"bitcoin"},{"id":37,"name":"blockchain"},{"id":1,"name":"blog"},{"id":45,"name":"bundler"},{"id":58,"name":"cache"},{"id":21,"name":"chat"},{"id":49,"name":"cicd"},{"id":4,"name":"cli"},{"id":64,"name":"cloud-native"},{"id":48,"name":"cms"},{"id":61,"name":"compiler"},{"id":68,"name":"containerization"},{"id":92,"name":"crm"},{"id":34,"name":"data"},{"id":47,"name":"database"},{"id":8,"name":"declarative-gui "},{"id":9,"name":"deploy-tool"},{"id":53,"name":"desktop-app"},{"id":6,"name":"dev-exp-lib"},{"id":59,"name":"dev-tool"},{"id":13,"name":"ecommerce"},{"id":26,"name":"editor"},{"id":66,"name":"emulator"},{"id":62,"name":"filesystem"},{"id":80,"name":"finance"},{"id":15,"name":"firmware"},{"id":73,"name":"for-fun"},{"id":2,"name":"framework"},{"id":11,"name":"frontend"},{"id":22,"name":"game"},{"id":81,"name":"game-engine "},{"id":23,"name":"graphql"},{"id":84,"name":"gui"},{"id":91,"name":"http"},{"id":5,"name":"http-client"},{"id":51,"name":"iac"},{"id":30,"name":"ide"},{"id":78,"name":"iot"},{"id":40,"name":"json"},{"id":83,"name":"julian"},{"id":38,"name":"k8s"},{"id":31,"name":"language"},{"id":10,"name":"learning-resource"},{"id":33,"name":"lib"},{"id":41,"name":"linter"},{"id":28,"name":"lms"},{"id":16,"name":"logging"},{"id":76,"name":"low-code"},{"id":90,"name":"message-queue"},{"id":42,"name":"mobile-app"},{"id":18,"name":"monitoring"},{"id":36,"name":"networking"},{"id":7,"name":"node-version"},{"id":55,"name":"nosql"},{"id":57,"name":"observability"},{"id":46,"name":"orm"},{"id":52,"name":"os"},{"id":14,"name":"parser"},{"id":74,"name":"react"},{"id":82,"name":"real-time"},{"id":56,"name":"robot"},{"id":65,"name":"runtime"},{"id":32,"name":"sdk"},{"id":71,"name":"search"},{"id":63,"name":"secrets"},{"id":25,"name":"security"},{"id":85,"name":"server"},{"id":86,"name":"serverless"},{"id":70,"name":"storage"},{"id":75,"name":"system-design"},{"id":79,"name":"terminal"},{"id":29,"name":"testing"},{"id":12,"name":"ui"},{"id":50,"name":"ux"},{"id":88,"name":"video"},{"id":20,"name":"web-app"},{"id":35,"name":"web-server"},{"id":43,"name":"webassembly"},{"id":69,"name":"workflow"},{"id":87,"name":"yaml"}]" returns me the "expected json"