Exploitation for Privilege Escalation T0890

ICS Tactic: Privilege Escalation

Authoring guide

Patterns shared across the 4 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.

Fields filtered most (13 distinct)

The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.

FieldRulesHowSample values
Category2eq 2ApplicationGatewayFirewallLog, FrontDoorWebApplicationFirewallLog
Total_TransactionId2ge 23
action_s2eq 2AnomalyScoring, Block, Blocked, Matched
Action1eq 1Blocked, Matched
Blocked_Reason1contains 1sql injection attack
DeviceProduct1eq 1iSID
EventClassID1in 1179, 34, 53
EventMessage1contains 1exploit
Message1contains 1sql injection
SQLI_Score1ge 110
TotalInboundScore1ge 115
Total_TrackingReference1ge 11
details_msg_s1contains 1sql injection

Top indicator values (25 distinct)

Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.

FieldKindValueRules (here)Corpus reach
Total_TransactionIdge
3
26
Actioneq
Blocked
16
Actioneq
Matched
15
Blocked_Reasoncontains
sql injection attack
1
Categoryeq
ApplicationGatewayFirewallLog
12
Categoryeq
FrontDoorWebApplicationFirewallLog
14
DeviceProducteq
iSID
18
EventClassIDin
179
1
EventClassIDin
34
1
EventClassIDin
53
1
EventClassIDin
67
1
EventClassIDin
68
1
EventClassIDin
69
1
EventClassIDin
70
1
EventClassIDin
71
1
EventMessagecontains
exploit
1
Messagecontains
sql injection
1
SQLI_Scorege
10
1
TotalInboundScorege
15
12
Total_TrackingReferencege
1
12
action_seq
AnomalyScoring
14
action_seq
Block
14
action_seq
Blocked
12
action_seq
Matched
12
details_msg_scontains
sql injection
1

Rules under this technique

Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.

Platform (all)
Domain (all)

Kusto 4 rules