Exploitation for Privilege Escalation T1068

Tactic: Privilege Escalation

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Events covered

42 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 6Driver loaded
SysmonEvent ID 7Image loaded
SysmonEvent ID 10ProcessAccess
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 15FileCreateStreamHash
SysmonEvent ID 22DNSEvent (DNS query)
SysmonEvent ID 23FileDelete (File Delete archived)
SysmonEvent ID 26FileDeleteDetected (File Delete logged)
Security-AuditingEvent ID 4657A registry value was modified.
Security-AuditingEvent ID 4673A privileged service was called.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4723An attempt was made to change an account's password.
Security-AuditingEvent ID 4724An attempt was made to reset an account's password.
Security-AuditingEvent ID 4741A computer account was created.
Security-AuditingEvent ID 4742A computer account was changed.
Security-AuditingEvent ID 4768A Kerberos authentication ticket (TGT) was requested.
Security-AuditingEvent ID 4769A Kerberos service ticket was requested.
Security-AuditingEvent ID 4781The name of an account was changed.
Security-AuditingEvent ID 4887Certificate Services approved a certificate request and issued a certificate.
Security-AuditingEvent ID 5136A directory service object was modified.
Defender-DeviceEventsanyDefender event
Defender-DeviceFileEventsanyFile activity
Defender-DeviceFileEventsFileCreatedFile created
Defender-DeviceNetworkEventsNetworkSignatureInspectedNetwork signature inspected
Defender-DeviceProcessEventsanyProcess activity
Defender-DeviceTvmSoftwareVulnerabilitiesanySoftware vulnerabilities on devices
ESFexecProcess Execution
ESFxpc_connectXPC Service Connection
Linux-AuditdEvent ID 1300SYSCALL
Linux-AuditdEvent ID 1302PATH
Linux-AuditdEvent ID 1309EXECVE
Linux-AuditdEvent ID 1321BPRM_FCAPS
Audit-CVEEvent ID 1Possible detection of CVE: PossibleDetectionOfCVE.
Windows-DefenderEvent ID 1116Product Name has detected malware or other potentially unwanted software.
Windows-DefenderEvent ID 1117Product Name has taken action to protect this machine from malware or other potentially unwanted software.
Service-Control-ManagerEvent ID 7045A service was installed in the system.
Sysmon-for-LinuxEvent ID 1Process Create
Sysmon-for-LinuxEvent ID 11File created

Authoring guide

These 237 rules share fields, values, and exclusions.

Fields filtered most (218 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType78eq 66, in 9, ne 7, wildcard 1exec, start, uid_change, deletion, ProcessRollup2
event.type56eq 52, ne 3, in 1start, change, deletion, creation, process_started
process_name53eq 34, in 14, starts_with 5, is_not_null 4, ends_with 2, contains 1, ne 1, regex_match 1, wildcard 1bash, sudo, dash, aa-exec, cmd.exe
host.os.type41eq 41
Image40ends_with 14, starts_with 11, eq 6, wildcard 5, in 4, is_not_null 4, ne 3, contains 2, is_null 1, regex_match 1/dev/shm/, /home/*/*, .*, /dev/shm/*, *\\\\*
user.id39eq 28, ne 23, is_not_null 5, starts_with 2, ge 1, wildcard 10, S-1-5-18, s-1-5-18, 1000, S-1-12-
process.args35eq 20, in 12, wildcard 8, starts_with 7, contains 2, ends_with 2-R, -m, -o, -*f*, --user
CommandLine32contains 23, in 4, regex_match 3, is_not_null 2, starts_with 2, ends_with 1, eq 1, wildcard 1sudo --chroot, --chroot , -p , -u#, /account
TargetFilename30wildcard 11, contains 8, starts_with 6, ends_with 5, in 3, eq 2.sys, /*/etc/nsswitch.conf, /*gconv_path*, /etc/passwd, ?:\config.msi\
EventID29eq 26, in 311, 1, 4688, 10, 23
ParentImage24wildcard 9, ends_with 5, eq 3, in 3, starts_with 3, is_not_null 2, regex_match 1/home/*/*, /dev/shm/*, .*, ./*, *\\\\*
parent_process_name21eq 13, in 6, wildcard 3, regex_match 2bash, .*, bun, (?i):\x5cWindows\x5csystem32\x5cconsent\.exe, brave.exe
user12eq 8, in 2, contains 1, cross_field_compare 1root, *$, *authority*, *system*, 0
process.parent.user.id10ne 8, ge 20, 1000
file.extension9eq 9dll, exe, rbs, blf, spl

Top indicator values (6945 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
461087
event.typeeq
change
1795
EventTypeeq
exec
38579
EventTypeeq
start
12392
EventTypeeq
uid_change
1219
user.ideq
0
2028
user.idne
0
1928
IntegrityLeveleq
System
831
ParentImagewildcard
/home/*/*
818
ParentImagewildcard
/dev/shm/*
617
ParentImagewildcard
/run/user/*
616
ParentImagewildcard
/tmp/*
619
ParentImagewildcard
/var/run/user/*
616
ParentImagewildcard
/var/tmp/*
619
process.parent.user.idne
0
813
EventTypene
deletion
787
process.Ext.token.integrity_level_nameeq
system
714
process.group.ideq
0
710
process.real_group.idne
0
79
process.real_user.idne
0
79
process.user.ideq
0
710
EventTypein
exec
6206
Imagestarts_with
/dev/shm/
653
Imagestarts_with
/tmp/
658
Imagestarts_with
/var/tmp/
656
event.categoryeq
process
6141
process.code_signature.existseq
false
6119
process.code_signature.trustedeq
false
6115
process.parent.group.idne
0
611
process_namein
bash
6202

Exclusions (983 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
user.ideq
s-1-5-18
7
process.code_signature.trustedeq
true
5
Imageeq
?:\windows\system32\werfault.exe
3
Imagestarts_with
/tmp/newroot/
3
Imagewildcard
/run/user/*/.bubblewrap/*
3
Imagewildcard
/tmp/newroot/*
3
Imagewildcard
/tmp/newroot/usr/bin/sudo
3
ParentImagestarts_with
/tmp/newroot/
3
ParentImagewildcard
/home/*/.bun/bin/bun
3
ParentImagewildcard
/home/*/.conda/envs/fmf_server_agent/bin/python*
3
ParentImagewildcard
/home/*/.local/bin/agy
3
ParentImagewildcard
/home/*/.local/bin/copilot
3
ParentImagewildcard
/home/*/.local/share/containers/storage/overlay/*
3
ParentImagewildcard
/home/*/.local/share/mise/installs/node/*/bin/node
3
ParentImagewildcard
/tmp/go-build*/*/sso.test
3

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 37 rules

Elastic 116 rules

Splunk 61 rules

Kusto 20 rules

YARA-L 1 rule

Panther 2 rules