Exploitation for Privilege Escalation T1068
Tactic: Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Events covered
40 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 231 rules share fields, values, and exclusions.
Fields filtered most (211 distinct)
These fields appear most often in rule filters.
Top indicator values (6908 distinct)
These values appear most often in rule predicates.
Exclusions (973 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 37 rules
- Audit CVE Event
- Authencesn Crypto Module Load via Modprobe - Copy-Fail Indicator
- Buffer Overflow Attempts
- Computer account created with privileges
- Computer account renamed without a trailing $ (CVE-2021-42278/42287)
- Exploiting CVE-2019-1388
- Exploiting SetupComplete.cmd CVE-2019-1378
- HackTool - SysmonEOP Execution
- HKTL - SharpSuccessor Privilege Escalation Tool Execution
- InstallerFileTakeOver LPE CVE-2021-41379 File Create Event
- Kerberos ticket without a trailing $ (CVE-2021-42278/42287)
- Linux AF_ALG Socket Creation - Kernel Crypto API Exploit Indicator
- Linux Sudo Chroot Execution
- macOS Setuid/Setgid Privilege Escalation
- Malicious Driver Load
- Malicious Driver Load By Name
- Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation
- OMIGOD HTTP No Authentication RCE - CVE-2021-38647
- OMIGOD SCX RunAsProvider ExecuteScript
- OMIGOD SCX RunAsProvider ExecuteShellCommand
- Possible Coin Miner CPU Priority Param
- Potential CVE-2021-41379 Exploitation Attempt
- Potential CVE-2024-35250 Exploitation Activity
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)
- Potential Nimbuspwn Exploit CVE-2022-29799 and CVE-2022-27800
- Potential SystemNightmare Exploitation Attempt
- Privilege SeMachineAccountPrivilege abuse
- Process Explorer Driver Creation By Non-Sysinternals Binary
- Process Monitor Driver Creation By Non-Sysinternals Binary
- Sudo Privilege Escalation CVE-2019-14287
- Sudo Privilege Escalation CVE-2019-14287 - Builtin
- Suspicious Kerberos proxiable/S4U2self ticket (CVE-2021-42278/42287)
- Suspicious Spool Service Child Process
- Suspicious Sysmon as Execution Parent
- Vulnerable Driver Load
- Vulnerable Driver Load By Name
- XPC Privilege Escalation Attempt
Elastic 117 rules
- Anomalous Linux Compiler Activity
- BLF File Creation by an Unusual Process
- CVE-2023-0386 Exploitation Attempt
- Deprecated - Suspicious PrintSpooler Service Executable File Creation
- Driver Dropped by Untrusted Executable
- Elevation via Common Log File System Exploitation
- Expired or Revoked Driver Loaded
- Exploit - Detected - Elastic Endgame
- Exploit - Prevented - Elastic Endgame
- First Time Seen Driver Loaded
- General Privilege Escalation Sequence Detected
- Kernel Driver Registered via NtLoadDriver
- Modification of the msPKIAccountCredentials
- MSI Rollback Script File by Unusual Process
- Persistence via Update Orchestrator Service Hijack
- Potential Buffer Overflow Attack Detected
- Potential CertiGhost AD CS Machine Identity Mismatch (CVE-2026-54121)
- Potential Cgroup Privilege Escalation/Container Escape via Mount
- Potential Common Log File System Exploit
- Potential Common Log File System Vulnerability Exploitation
- Potential Copy Fail (CVE-2026-31431) Exploitation via AF_ALG Socket
- Potential CVE-2024-21338 Exploitation
- Potential CVE-2025-32463 Nsswitch File Creation
- Potential CVE-2025-32463 Nsswitch File Creation
- Potential CVE-2025-32463 Sudo Chroot Execution Attempt
- Potential CVE-2025-32463 Sudo Chroot Execution Attempt
- Potential Escalation via Vulnerable MSI Repair
- Potential Exploitation via ComDotNet Exploit
- Potential Local Privilege Escalation via a Suspicious Descendant Process
- Potential Local Privilege Escalation via Unshare
- Potential PackageKit TOCTOU Privilege Escalation via CVE-2026-41651
- Potential Privilege Escalation via a Known SUID/SGID Binary
- Potential Privilege Escalation via a Parent Process Sequence
- Potential Privilege Escalation via a Parent/Child Process Sequence
- Potential Privilege Escalation via a SUID/SGID Binary
- Potential Privilege Escalation via a Suspicious UID Change
- Potential Privilege Escalation via Busctl System Call
- Potential privilege escalation via CVE-2022-38028
- Potential privilege escalation via CVE-2022-38028
- Potential Privilege Escalation via CVE-2023-4911
- Potential Privilege Escalation via Enlightenment
- Potential Privilege Escalation via Fuse Binary
- Potential Privilege Escalation via InstallerFileTakeOver
- Potential Privilege Escalation via Linux DAC permissions
- Potential Privilege Escalation via LocalPotato Exploit
- Potential Privilege Escalation via LogonUI
- Potential Privilege Escalation via MSI Repair
- Potential Privilege Escalation via OverlayFS
- Potential Privilege Escalation via PKEXEC
- Potential Privilege Escalation via Python cap_setuid
- Potential Privilege Escalation via Python Exploit
- Potential Privilege Escalation via Recently Compiled Executable
- Potential Privilege Escalation via RoguePlanet Windows Defender Exploit
- Potential Privilege Escalation via SUID Binary
- Potential Privilege Escalation via SUID/SGID Proxy Execution
- Potential Privilege Escalation via SUID/SGID Proxy Execution
- Potential Privilege Escalation via TCC bypass with fake TCC.db
- Potential Privilege Escalation via unshare and UID Change
- Potential Privilege Escalation via unshare Followed by Root Process
- Potential Privileged Escalation via SamAccountName Spoofing
- Potential Shadow File Read via Command Line Utilities
- Potential Shadow Read via Unprivileged User
- Potential Shell via Wildcard Injection Detected
- Potential SIP Bypass via the ShoveService
- Potential snap-confine Privilege Escalation via CVE-2026-3888
- Potential Sudo Privilege Escalation via CVE-2019-14287
- Potential Sudo Privilege Escalation via CVE-2019-14287
- Potential Telnet Authentication Bypass (CVE-2026-24061)
- Potential Unauthorized Access via Wildcard Injection Detected
- Privilege Escalation via CAP_CHOWN/CAP_FOWNER Capabilities
- Privilege Escalation via CAP_SETUID/SETGID Capabilities
- Privilege Escalation via GDB CAP_SYS_PTRACE
- Privilege Escalation via NTLMRelay2Self
- Privilege Escalation via PKEXEC Exploitation
- Privilege Escalation via SUID/SGID
- Privilege Escalation via Windows Installer Hijack
- Process Explorer Device Access by Unusual Process
- Process Suspended via TTD Monitor Driver
- Remote Computer Account DnsHostName Update
- Root Network Connection via GDB CAP_SYS_PTRACE
- Shell Privileged Mode from Non-Standard Path with Root Effective User
- Spike in Group Application Assignment Change Events
- Spike in Group Lifecycle Change Events
- Spike in Group Membership Events
- Spike in Group Privilege Change Events
- Spike in host-based traffic
- Spike in Special Logon Events
- Spike in Special Privilege Use Events
- Spike in User Account Management Events
- Sudo Heap-Based Buffer Overflow Attempt
- Suspicious Child Process of Adobe Acrobat Reader Update Service
- Suspicious Desktop Window Manager API Call
- Suspicious DNS Lookup for Microsoft Defender Definition Updates
- Suspicious Execution as System via Windows Command Shell
- Suspicious Kernel Mode Address Manipulation
- Suspicious NtOSKrnl Image Load
- Suspicious Passwd File Event Action
- Suspicious Print Spooler File Deletion
- Suspicious Print Spooler Point and Print DLL
- Suspicious Print Spooler SPL File Created
- Suspicious Privileged Docker Execution
- Suspicious PrivilegedHelperTool Activity
- Suspicious SUID/SGID Utility Execution
- Suspicious System Path File Overwrite
- Suspicious UID Change to Root via Python
- Telnet Authentication Bypass via User Environment Variable
- UID Change to 0 from Unusual Process Executable
- Unsigned DLL loaded by DNS Service
- Unsigned DLL loaded by DNS Service
- Unusual Child Process Integrity Level
- Unusual Desktop Window Manager Child Process
- Unusual Executable File Creation by a System Critical Process
- Unusual Group Name Accessed by a User
- Unusual Print Spooler Child Process
- Unusual Privilege Escalation to System
- Unusual Privilege Type assigned to a User
- Unusual Spike in Concurrent Active Sessions by a User
Splunk 56 rules
- Child Processes of Spoolsv exe
- Cisco Isovalent - Kprobe Spike
- Consent.exe Suspicious Child Process (Sysmon)
- Consent.exe Suspicious Child Process (Windows Event Log)
- Detect Baron Samedit CVE-2021-3156
- Detect Baron Samedit CVE-2021-3156 Segfault
- Detect Baron Samedit CVE-2021-3156 via OSQuery
- Driver as Command Parameter (Windows Event Log)
- Driver Loaded from Unusual Path - Windows (Sysmon)
- Executable Running as NT AUTHORITY_SYSTEM Registered in BAM (Sysmon)
- Executable Running as NT AUTHORITY_SYSTEM Registered in BAM (Windows Event Log)
- First Time Seen Child Process of Zoom
- Kernel Service Installed - Windows (Windows Event Log)
- Linux Apparmor Bypass Via Aaexec
- Linux Auditd Copy Fail Privilege Escalation
- Linux Auditd Possible Setuid Execve Privesc
- Linux Binary Launched Process with Null Argv
- Linux Dirty Frag Kernel Privilege Escalation
- Linux Ghostscript Exploitation
- Linux Malformed Auth Entry
- Linux Pedit Offset Out Of Bounds
- Linux PF_ALG Registration Outside of Boot Window
- Linux pkexec Privilege Escalation
- Linux Possible GSM Privilege Escalation
- Linux Possible Nimbuspwn Privilege Escalation
- Linux Possible Privilege Escalation via PYTHONPATH
- Linux Suspicious GCC Invocation Building Init Shared Object
- Linux Suspicious Namespace Creation
- Microsoft SharePoint Server Elevation of Privilege
- Potential CVE-2021-4034
- Spoolsv Suspicious Process Access
- Suspicious .sys Created - Windows (Sysmon)
- VMWare Aria Operations Exploit Attempt
- Windows Admin Password Changed by Non-Admin
- Windows Cloud Files Filter Log Created by Non-System Process
- Windows Driver Inventory
- Windows Driver Load Non-Standard Path
- Windows Drivers Loaded by Signature
- Windows MSI Rollback Script Deleted By Non-Msiexec Process
- Windows MsMpEng Writing to System32
- Windows Non-System Process Querying Definition Update
- Windows Potato Privilege Escalation Tool Execution
- Windows Privilege Escalation Attempt Via MSI Rollback
- Windows Privilege Escalation Suspicious Process Elevation
- Windows Privilege Escalation System Process Without System Parent
- Windows Privilege Escalation User Process Spawn System Process
- Windows Remote Image Load
- Windows Service Create Kernel Mode Driver
- Windows Suspicious Burst of Password Changes
- Windows Suspicious Child Process of Consent.EXE
- Windows Suspicious Child Process of TieringEngineService.exe
- Windows Suspicious Defender Engine or Signature Files Created
- Windows Suspicious Defender Update Activity in INetCache
- Windows System File on Disk
- Windows VSSVC Process Accessing Defender Engine
- ZeroLogon CVE-2020-1472 (Windows Event Log)
Kusto 18 rules
- CTERA Mass Permissions Changes Detection Analytic
- Detect CVE exploits on network for which a device is vulnerable
- Detect LolDriver drop or load from unknown or unsigned process
- Dynatrace Application Security - Attack detection
- Email access via active sync
- GitHub Security Vulnerability in Repository
- Google DNS - CVE-2020-1350 (SIGRED) exploitation pattern
- Google DNS - CVE-2021-34527 (PrintNightmare) external exploit
- Google DNS - CVE-2021-40444 exploitation
- GTI - High Relevance Alert Detected
- GTI - Insider Threat Alert Detected
- McAfee ePO - Threat was not blocked
- Power Platform - Account added to privileged Microsoft Entra roles
- Powershell Empire Cmdlets Executed in Command Line
- Rare application consent
- Semperis DSP Zerologon vulnerability
- Silverfort - Certifried Incident
- Silverfort - NoPacBreach Incident