Exploitation for Privilege Escalation T1068

Tactic: Privilege Escalation

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Events covered

40 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 6Driver loaded
SysmonEvent ID 7Image loaded
SysmonEvent ID 10ProcessAccess
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 15FileCreateStreamHash
SysmonEvent ID 22DNSEvent (DNS query)
SysmonEvent ID 23FileDelete (File Delete archived)
SysmonEvent ID 26FileDeleteDetected (File Delete logged)
Security-AuditingEvent ID 4657A registry value was modified.
Security-AuditingEvent ID 4673A privileged service was called.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4723An attempt was made to change an account's password.
Security-AuditingEvent ID 4724An attempt was made to reset an account's password.
Security-AuditingEvent ID 4741A computer account was created.
Security-AuditingEvent ID 4742A computer account was changed.
Security-AuditingEvent ID 4768A Kerberos authentication ticket (TGT) was requested.
Security-AuditingEvent ID 4769A Kerberos service ticket was requested.
Security-AuditingEvent ID 4781The name of an account was changed.
Security-AuditingEvent ID 4887Certificate Services approved a certificate request and issued a certificate.
Security-AuditingEvent ID 5136A directory service object was modified.
Defender-DeviceEventsanyDefender event
Defender-DeviceFileEventsanyFile activity
Defender-DeviceFileEventsFileCreatedFile created
Defender-DeviceNetworkEventsNetworkSignatureInspectedNetwork signature inspected
Defender-DeviceProcessEventsanyProcess activity
Defender-DeviceTvmSoftwareVulnerabilitiesanySoftware vulnerabilities on devices
ESFexecProcess Execution
ESFxpc_connectXPC Service Connection
Linux-AuditdEvent ID 1300SYSCALL
Linux-AuditdEvent ID 1302PATH
Linux-AuditdEvent ID 1309EXECVE
Linux-AuditdEvent ID 1321BPRM_FCAPS
Audit-CVEEvent ID 1Possible detection of CVE: PossibleDetectionOfCVE.
Service-Control-ManagerEvent ID 7045A service was installed in the system.
Sysmon-for-LinuxEvent ID 1Process Create
Sysmon-for-LinuxEvent ID 11File created

Authoring guide

These 231 rules share fields, values, and exclusions.

Fields filtered most (211 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType78eq 66, in 9, ne 7, wildcard 1exec, start, uid_change, deletion, ProcessRollup2
event.type57eq 53, ne 3, in 1start, change, creation, deletion, process_started
process_name54eq 35, in 14, starts_with 5, is_not_null 4, ends_with 2, contains 1, ne 1, regex_match 1, wildcard 1bash, sudo, dash, aa-exec, cmd.exe
host.os.type41eq 41
Image39ends_with 14, starts_with 11, eq 6, wildcard 5, is_not_null 4, in 3, ne 3, contains 2, is_null 1, regex_match 1/dev/shm/, /home/*/*, .*, /dev/shm/*, *\\\\*
user.id39eq 28, ne 23, is_not_null 5, starts_with 2, ge 1, wildcard 10, S-1-5-18, s-1-5-18, 1000, S-1-12-
process.args35eq 20, in 12, wildcard 8, starts_with 7, contains 2, ends_with 2-R, -m, -o, -*f*, --user
CommandLine32contains 23, in 4, regex_match 3, is_not_null 2, starts_with 2, ends_with 1, eq 1, wildcard 1sudo --chroot, --chroot , -p , -u#, /account
TargetFilename28wildcard 11, contains 7, starts_with 6, ends_with 5, eq 2, in 2.sys, /*/etc/nsswitch.conf, /*gconv_path*, /etc/passwd, ?:\config.msi\
EventID27eq 25, in 211, 1, 4688, 10, 23
ParentImage24wildcard 9, ends_with 5, eq 3, in 3, starts_with 3, is_not_null 2, regex_match 1/home/*/*, /dev/shm/*, .*, ./*, *\\\\*
parent_process_name20eq 12, in 6, wildcard 3, regex_match 2bash, .*, bun, (?i):\x5cWindows\x5csystem32\x5cconsent\.exe, brave.exe
user11eq 8, contains 1, cross_field_compare 1, in 1root, *authority*, *system*, 0, 501-65535
file.extension10eq 10dll, exe, rbs, blf, spl
process.parent.user.id10ne 8, ge 20, 1000

Top indicator values (6908 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
461078
event.typeeq
change
1794
EventTypeeq
exec
38576
EventTypeeq
start
12391
EventTypeeq
uid_change
1219
user.ideq
0
2028
user.idne
0
1928
ParentImagewildcard
/home/*/*
818
ParentImagewildcard
/dev/shm/*
617
ParentImagewildcard
/run/user/*
616
ParentImagewildcard
/tmp/*
619
ParentImagewildcard
/var/run/user/*
616
ParentImagewildcard
/var/tmp/*
619
process.parent.user.idne
0
813
EventTypene
deletion
786
IntegrityLeveleq
System
730
process.Ext.token.integrity_level_nameeq
system
714
process.group.ideq
0
710
process.real_group.idne
0
79
process.real_user.idne
0
79
process.user.ideq
0
710
EventTypein
exec
6201
Imagestarts_with
/dev/shm/
653
Imagestarts_with
/tmp/
658
Imagestarts_with
/var/tmp/
656
event.categoryeq
process
6142
process.code_signature.existseq
false
6119
process.code_signature.trustedeq
false
6115
process.parent.group.idne
0
611
process_namein
bash
6202

Exclusions (973 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
user.ideq
s-1-5-18
7
process.code_signature.trustedeq
true
5
Imageeq
?:\windows\system32\werfault.exe
3
Imagestarts_with
/tmp/newroot/
3
Imagewildcard
/run/user/*/.bubblewrap/*
3
Imagewildcard
/tmp/newroot/*
3
Imagewildcard
/tmp/newroot/usr/bin/sudo
3
ParentImagestarts_with
/tmp/newroot/
3
ParentImagewildcard
/home/*/.bun/bin/bun
3
ParentImagewildcard
/home/*/.conda/envs/fmf_server_agent/bin/python*
3
ParentImagewildcard
/home/*/.local/bin/agy
3
ParentImagewildcard
/home/*/.local/bin/copilot
3
ParentImagewildcard
/home/*/.local/share/containers/storage/overlay/*
3
ParentImagewildcard
/home/*/.local/share/mise/installs/node/*/bin/node
3
ParentImagewildcard
/tmp/go-build*/*/sso.test
3

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 37 rules

Elastic 117 rules

Splunk 56 rules

Kusto 18 rules

YARA-L 1 rule

Panther 2 rules