Abuse Elevation Control Mechanism: Elevated Execution with Prompt T1548.004
Tactic: Privilege Escalation
Adversaries may leverage the AuthorizationExecuteWithPrivileges API to escalate privileges by prompting the user for credentials. The purpose of this API is to give application developers an easy way to perform operations with root privileges, such as for application installation or updating. This API does not validate that the program requesting root privileges comes from a reputable source or has been maliciously modified.
Events covered
1 catalog event is tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| ESF | exec | Process Execution |
Authoring guide
These 3 rules share fields, values, and exclusions.
Fields filtered most (10 distinct)
These fields appear most often in rule filters.
Top indicator values (28 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: macOS
Domain: Endpoint