T1068 Exploitation for Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Exploiting CVE-2019-1388criticalstable · windows
- Audit CVE Eventcriticaltest · windows
- HackTool - SysmonEOP Executioncriticaltest · windows
- InstallerFileTakeOver LPE CVE-2021-41379 File Create Eventcriticaltest · windows
- Possible Coin Miner CPU Priority Paramcriticaltest · linux
- Potential CVE-2021-41379 Exploitation Attemptcriticaltest · windows
- Potential SystemNightmare Exploitation Attemptcriticaltest · windows
- Sudo Privilege Escalation CVE-2019-14287 - Builtincriticaltest · linux
- OMIGOD HTTP No Authentication RCE - CVE-2021-38647highstable · zeek
- Buffer Overflow Attemptshightest · linux
- Exploiting SetupComplete.cmd CVE-2019-1378hightest · windows
- Malicious Driver Loadhightest · windows
- OMIGOD SCX RunAsProvider ExecuteScripthightest · linux
- OMIGOD SCX RunAsProvider ExecuteShellCommandhightest · linux
- Potential Nimbuspwn Exploit CVE-2022-29799 and CVE-2022-27800hightest · linux
- Process Explorer Driver Creation By Non-Sysinternals Binaryhightest · windows
- Sudo Privilege Escalation CVE-2019-14287hightest · linux
- Suspicious Spool Service Child Processhightest · windows
- Suspicious Sysmon as Execution Parenthightest · windows
- Vulnerable Driver Loadhightest · windows
- Authencesn Crypto Module Load via Modprobe - Copy-Fail Indicatorhighexperimental · linux
- HKTL - SharpSuccessor Privilege Escalation Tool Executionhighexperimental · windows
- Linux AF_ALG Socket Creation - Kernel Crypto API Exploit Indicatorhighexperimental · linux
- Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitationhighexperimental · linux
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)highexperimental · windows
Showing 25 of 28.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.