Ok i'm still looking into this.
I tried a program called
It appears when ever UAC is called into action consent.exe runs. So I tried it with notepad and got ...
11:10:44.8360814 AM consent.exe 12136 QueryStandardInformationFile C:\Windows\System32\notepad.exe SUCCESS AllocationSize: 221,184, EndOfFile: 217,600, NumberOfLinks: 4, DeletePending: False, Directory: False
When just running it without admin it didn't show up at all
So I right clicked that entry and told it to just include that. Also added a filter for consent.exe. Also add a filter for
Path / Ends with / .exe / include.
Once you click accept on the UAC a single exe file should show up.
Then as a test, I ran CMD as admin and saw this ...Ta Da!