Abuse Elevation Control Mechanism T1548

Tactic: Privilege Escalation

Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk. An adversary can perform several methods to take advantage of built-in control mechanisms in order to escalate privileges on a system.

Events covered

33 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 5Process terminated
SysmonEvent ID 7Image loaded
SysmonEvent ID 10ProcessAccess
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4657A registry value was modified.
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4674An operation was attempted on a privileged object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4689A process has exited.
Defender-CloudAppEventsanyCloud app activity
Defender-DeviceRegistryEventsRegistryKeyDeletedRegistry key deleted
Defender-DeviceRegistryEventsRegistryValueSetRegistry value set
Defender-DeviceRegistryEventsRegistryValueDeletedRegistry value deleted
Defender-DeviceRegistryEventsRegistryKeyRenamedRegistry key renamed
Defender-IdentityInfoanyIdentity information
ESFexecProcess Execution
ESFopenFile Open
Linux-AuditdEvent ID 1300SYSCALL
Linux-AuditdEvent ID 1302PATH
Linux-AuditdEvent ID 1307CWD
Linux-AuditdEvent ID 1309EXECVE
Linux-AuditdEvent ID 1321BPRM_FCAPS
Linux-AuditdEvent ID 1327PROCTITLE
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
NETLOGONEvent ID 5829The Netlogon service allowed a vulnerable Netlogon secure channel connection.
Sysmon-for-LinuxEvent ID 1Process Create
Sysmon-for-LinuxEvent ID 11File created

Authoring guide

These 366 rules share fields, values, and exclusions.

Fields filtered most (194 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType95eq 78, in 19, ne 2exec, start, uid_change, rename, exec_event
process_name79eq 55, in 18, starts_with 6, regex_match 5, is_not_null 3, ends_with 2, contains 1, ne 1dllhost.exe, bash, chmod, sudo, setcap
CommandLine67contains 51, eq 11, wildcard 7, in 5, ends_with 3, regex_match 3, starts_with 2, match 1sudo, --eval, (?i)ms-settings\x5cshell\x5copen\x5ccommand.+, *scp *127.0.0.?:/*, *scp *localhost:/*
event.type63eq 54, in 7, ne 2start, change, process_started, creation, deletion
Image57ends_with 28, wildcard 9, is_not_null 7, contains 5, eq 5, starts_with 4, in 2/dev/shm/*, /home/*/*, .*, \dism.exe, \powershell.exe
host.os.type54eq 53, in 1
parent_process_name48eq 29, in 13, wildcard 7, regex_match 4, cross_field_compare 1bash, .*, bun, csh, dash
process.args39eq 23, in 14, wildcard 10, starts_with 5, contains 2, regex_match 1+x, --command, -2000, -4000, -6000
ParentImage36ends_with 19, wildcard 10, contains 3, eq 2, in 2, is_not_null 1, starts_with 1/dev/shm/*, /home/*/*, ./*, .*, \dllhost.exe
TargetFilename32starts_with 14, ends_with 11, wildcard 11, eq 4, in 3, contains 2, regex_match 1c:\users\, /etc/doas.conf, /etc/sudoers, (?i)^c:\\users\\[^\\]+\\ntuser\.dat$, .dll
EventID25eq 254688, 1, 4657, 13, 4103
TargetObject23contains 9, ends_with 8, wildcard 6, eq 1software\classes\ms-settings\shell\open\command, *\ms-windows-store*, \appx82a6gwre4fdg3bt635tn5ctqjf8msdd2\shell\open\command, \environment\windir, \lowercaselongpath
process.Ext.token.integrity_level_name23eq 23high, system, medium
IntegrityLevel22eq 20, in 4High, System, Low, Medium
Details20eq 13, contains 3, ends_with 3, is_not_null 2, regex_match 1, starts_with 10x00000000, (empty), .dll, 0, 0x00000001

Top indicator values (2353 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
501078
event.typeeq
change
1494
EventTypeeq
exec
35576
EventTypeeq
start
25391
EventTypeeq
uid_change
819
CommandLinecontains
sudo
2224
process.Ext.token.integrity_level_nameeq
high
2122
IntegrityLeveleq
System
1930
IntegrityLeveleq
High
1621
event.outcomeeq
success
12369
user.idne
0
1228
user.ideq
0
1128
EventIDeq
4688
10317
EventIDeq
1
8241
parent_process_namein
bash
1065
parent_process_namein
csh
1039
parent_process_namein
dash
1042
parent_process_namein
fish
1040
parent_process_namein
ksh
1040
parent_process_namein
sh
1065
parent_process_namein
tcsh
1040
parent_process_namein
zsh
1063
process.group.ideq
0
1010
process.user.ideq
0
1010
process.real_group.idne
0
99
process.real_user.idne
0
99
process_nameeq
dllhost.exe
919
EventTypein
exec
8201
ParentImagewildcard
/dev/shm/*
817
ParentImagewildcard
/home/*/*
818

Exclusions (701 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imageeq
?:\windows\system32\werfault.exe
13
Imageeq
?:\windows\syswow64\werfault.exe
13
Imageeq
?:\windows\system32\wermgr.exe
6
Imageeq
?:\windows\syswow64\wermgr.exe
6
Imageeq
?:\windows\system32\conhost.exe
3
process.code_signature.trustedeq
true
7
Imagein
/usr/bin/sudo
4
Imagein
/bin/sudo
3
Imagewildcard
?:\program files (x86)\*.exe
3
Imagewildcard
?:\program files\*.exe
3
Imagewildcard
?:\windows\system32\mmc.exe
3
Imagewildcard
?:\windows\syswow64\mmc.exe
3
ParentImagewildcard
/tmp/newroot/*
3
aws::userIdentity.typeeq
awsservice
3
dll.code_signature.subject_namestarts_with
Microsoft
3

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 90 rules

Elastic 120 rules

Splunk 90 rules

Kusto 46 rules

Panther 20 rules