T1548 โ Abuse Elevation Control Mechanism
Parent technique
Description
Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk. An adversary can perform several methods to take advantage of built-in control mechanisms in order to escalate privileges on a system.
Sub-techniques
- T1548.001 โ Setuid and Setgid
- T1548.002 โ Bypass User Account Control
- T1548.003 โ Sudo and Sudo Caching
- T1548.004 โ Elevated Execution with Prompt
- T1548.005 โ Temporary Elevated Cloud Access
- T1548.006 โ TCC Manipulation
Detected by EasySIEM
This project's own SigmaHQ-derived detection pipeline tags every compiled rule with the ATT&CK technique(s) it maps to -- if a rule in your install covers this technique, it shows up automatically on your own Grafana Alerts dashboard's "Top ATT&CK Techniques" panel, no lookup needed. This page exists so a click from there always lands here on easysiem.com, not on attack.mitre.org.