{"id":"T1068","name":"Exploitation for Privilege Escalation","url":"https://attack.mitre.org/techniques/T1068","tactics":["privilege-escalation"],"platforms":["Containers","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0514","stix_id":"x-mitre-detection-strategy--64fc24f5-0428-4956-a328-2e76e0af984e","name":"Detection Strategy for Exploitation for Privilege Escalation","url":"https://attack.mitre.org/detectionstrategies/DET0514","analytics":[{"id":"AN1419","stix_id":"x-mitre-analytic--b01d212c-112a-47fb-8883-78bb623ee34b","name":"Analytic 1419","description":"Detects exploitation attempts targeting vulnerable kernel drivers or OS components, often followed by unusual process or token behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0514#AN1419","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=6","data_component":"DC0079","data_component_name":"Driver Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4672","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"DriverNamePattern","description":"Targeted BYOVD drivers may vary based on campaign and tooling."},{"field":"TimeWindow","description":"Controls temporal linking of driver load → process spawn → privilege use."},{"field":"ParentProcessPath","description":"Parent-child relationships vary by exploitation vector (e.g., LOLBin vs. dropper)."}],"live":true,"detection_strategies":["DET0514"],"techniques":["T1068"]},{"id":"AN1420","stix_id":"x-mitre-analytic--1327b96f-73db-4a5e-8e71-e515fc030bf3","name":"Analytic 1420","description":"Detects escalation via vulnerable setuid binaries or kernel modules, often chained with unusual access to /proc/kallsyms or /dev/kmem.","url":"https://attack.mitre.org/detectionstrategies/DET0514#AN1420","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"ACCESS","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"dmesg","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"SetUIDBinaryList","description":"Legitimate SUID binaries vary across distributions; false positives may arise."},{"field":"TimeWindow","description":"Allows chaining kernel module load with privilege spike or privilege-sensitive process activity."},{"field":"EffectiveUIDThreshold","description":"Default is uid=0, but environments may vary with containerized root-like accounts."}],"live":true,"detection_strategies":["DET0514"],"techniques":["T1068"]},{"id":"AN1421","stix_id":"x-mitre-analytic--0066bac9-599a-4f7b-a667-9cb1dca94347","name":"Analytic 1421","description":"Detects use of vulnerable kernel extensions or entitlements abused via setuid or AppleScript injection chains.","url":"https://attack.mitre.org/detectionstrategies/DET0514#AN1421","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process:exec and kext load events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_KEXTLOAD","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"macos-endpointsecurity"}],"mutable_elements":[{"field":"EntitlementList","description":"Entitlements vary by app and OS version; some allow unexpected behavior."},{"field":"TimeWindow","description":"Correlate SUID execution or AppleScript injection with privilege gain or module load."}],"live":true,"detection_strategies":["DET0514"],"techniques":["T1068"]},{"id":"AN1422","stix_id":"x-mitre-analytic--2a93100f-6332-4c91-bad9-fd371d638309","name":"Analytic 1422","description":"Detects container breakout behavior via exploitation (e.g., DirtyPipe, CVE-2022-0847), followed by host OS interaction or escalated capability assignment.","url":"https://attack.mitre.org/detectionstrategies/DET0514#AN1422","platforms":["Containers"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"capset or setns","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"auditd-syscall"},{"name":"containerd:runtime","channel":"e.g., containerd, Docker events","data_component":"DC0091","data_component_name":"Container Enumeration","log_source_slug":"containerd-runtime"}],"mutable_elements":[{"field":"NamespaceEscapePattern","description":"May vary with CVE technique or custom syscall wrapper."},{"field":"TimeWindow","description":"Controls correlation of breakout → host interaction."}],"live":true,"detection_strategies":["DET0514"],"techniques":["T1068"]}],"live":true,"version":"1.0","techniques":["T1068"]}],"sigma_rules":[{"id":"02e0b2ea-a597-428e-b04a-af6a1a403e5c","title":"Exploiting CVE-2019-1388","author":"Florian Roth (Nextron Systems)","status":"stable","level":"critical","date":"2019-11-20","modified":"2024-12-01","description":"Detects an exploitation attempt in which the UAC consent dialogue is used to invoke an Internet Explorer process running as LOCAL_SYSTEM","references":["https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1388","https://www.zerodayinitiative.com/blog/2019/11/19/thanksgiving-treat-easy-as-pie-windows-7-secure-desktop-escalation-of-privilege"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1068","cve.2019-1388","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Exploits/CVE-2019-1388/proc_creation_win_exploit_cve_2019_1388.yml","techniques":["T1068"],"cves":["CVE-2019-1388"]},{"id":"05296024-fe8a-4baf-8f3d-9a5f5624ceb2","title":"Malicious Driver Load","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-18","modified":"2023-12-02","description":"Detects loading of known malicious drivers via their hash.","references":["https://loldrivers.io/"],"logsource":{"product":"windows","category":"driver_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003","attack.t1068"],"path":"rules/windows/driver_load/driver_load_win_mal_drivers.yml","techniques":["T1543.003","T1068"],"cves":[]},{"id":"071d5e5a-9cef-47ec-bc4e-a42e34d8d0ed","title":"Possible Coin Miner CPU Priority Param","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-10-09","modified":"2022-12-25","description":"Detects command line parameter very often used with coin miners","references":["https://xmrig.com/docs/miner/command-line-options"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.privilege-escalation","attack.t1068"],"path":"rules/linux/auditd/execve/lnx_auditd_coinminer.yml","techniques":["T1068"],"cves":[]},{"id":"0fdc7c7f-c690-4217-9ae3-31f5156eed72","title":"Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)","author":"Nisarg Suthar","status":"experimental","level":"high","date":"2025-08-01","modified":null,"description":"Detects suspicious child processes created by CrushFTP. It could be an indication of exploitation of a RCE vulnerability such as CVE-2025-54309.","references":["https://reliaquest.com/blog/threat-spotlight-cve-2025-54309-crushftp-exploit/","https://pwn.guide/free/web/crushftp","https://firecompass.com/crushftp-vulnerability-cve-2025-54309-securing-file-transfer-services/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.initial-access","attack.execution","attack.t1059.001","attack.t1059.003","attack.t1068","attack.t1190","cve.2025-54309","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-54309/proc_creation_win_exploit_cve_2025_54309.yml","techniques":["T1059.001","T1059.003","T1068","T1190"],"cves":["CVE-2025-54309"]},{"id":"10ac0730-c24e-4f4c-81f8-b13a1ac95a1d","title":"Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation","author":"Swachchhanda Shrawn Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-10-02","modified":"2026-03-31","description":"Detects the creation of nsswitch.conf files in non-standard directories, which may indicate exploitation of CVE-2025-32463.\nThis vulnerability requires an attacker to create a nsswitch.conf in a directory that will be used during sudo chroot operations.\nWhen sudo executes, it loads malicious shared libraries from user-controlled locations within the chroot environment,\npotentially leading to arbitrary code execution and privilege escalation.\n","references":["https://github.com/kh4sh3i/CVE-2025-32463/blob/81bb430f84fa2089224733c3ed4bfa434c197ad4/exploit.sh"],"logsource":{"product":"linux","category":"file_event"},"tags":["attack.privilege-escalation","attack.t1068","cve.2025-32463","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-32463/file_event_lnx_exploit_cve_2025_32463.yml","techniques":["T1068"],"cves":["CVE-2025-32463"]},{"id":"17ce9373-2163-4a2c-90ba-f91e9ef7a8c1","title":"Potential CVE-2024-35250 Exploitation Activity","author":"@eyezuhk Isaac Fernandes","status":"experimental","level":"medium","date":"2025-02-19","modified":null,"description":"Detects potentially suspicious loading of \"ksproxy.ax\", which may indicate an attempt to exploit CVE-2024-35250.\n","references":["https://thehackernews.com/2024/12/cisa-and-fbi-raise-alerts-on-exploited.html","https://github.com/varwara/CVE-2024-35250","https://devco.re/blog/2024/08/23/streaming-vulnerabilities-from-windows-kernel-proxying-to-kernel-part1-en/","https://www.cisa.gov/known-exploited-vulnerabilities-catalog"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.t1068","cve.2024-35250","detection.emerging-threats"],"path":"rules-emerging-threats/2024/Exploits/CVE-2024-35250/image_load_exploit_cve_2024_35250_privilege_escalation.yml","techniques":["T1068"],"cves":["CVE-2024-35250"]},{"id":"18b042f0-2ecd-4b6e-9f8d-aa7a7e7de781","title":"Buffer Overflow Attempts","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-03-01","modified":"2025-03-17","description":"Detects buffer overflow attempts in Unix system log files","references":["https://github.com/ossec/ossec-hids/blob/1ecffb1b884607cb12e619f9ab3c04f530801083/etc/rules/attack_rules.xml","https://docs.oracle.com/cd/E19683-01/816-4883/6mb2joatd/index.html","https://www.giac.org/paper/gcih/266/review-ftp-protocol-cyber-defense-initiative/102802","https://blu.org/mhonarc/discuss/2001/04/msg00285.php","https://rapid7.com/blog/post/2019/02/19/stack-based-buffer-overflow-attacks-what-you-need-to-know/"],"logsource":{"product":"linux"},"tags":["attack.t1068","attack.privilege-escalation"],"path":"rules/linux/builtin/lnx_buffer_overflows.yml","techniques":["T1068"],"cves":[]},{"id":"1c373b6d-76ce-4553-997d-8c1da9a6b5f5","title":"Exploiting SetupComplete.cmd CVE-2019-1378","author":"Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro","status":"test","level":"high","date":"2019-11-15","modified":"2021-11-27","description":"Detects exploitation attempt of privilege escalation vulnerability via SetupComplete.cmd and PartnerSetupComplete.cmd described in CVE-2019-1378","references":["https://web.archive.org/web/20200530031708/https://www.embercybersecurity.com/blog/cve-2019-1378-exploiting-an-access-control-privilege-escalation-vulnerability-in-windows-10-update-assistant-wua"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1068","attack.execution","attack.t1059.003","attack.t1574","cve.2019-1378","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Exploits/CVE-2019-1378/proc_creation_win_exploit_cve_2019_1378.yml","techniques":["T1068","T1059.003","T1574"],"cves":["CVE-2019-1378"]},{"id":"21541900-27a9-4454-9c4c-3f0a4240344a","title":"OMIGOD SCX RunAsProvider ExecuteShellCommand","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC","status":"test","level":"high","date":"2021-10-15","modified":"2022-10-05","description":"Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell.\nSCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including\nMicrosoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.\n","references":["https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure","https://github.com/Azure/Azure-Sentinel/pull/3059"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.privilege-escalation","attack.initial-access","attack.execution","attack.t1068","attack.t1190","attack.t1203"],"path":"rules/linux/process_creation/proc_creation_lnx_omigod_scx_runasprovider_executeshellcommand.yml","techniques":["T1068","T1190","T1203"],"cves":[]},{"id":"38a1ac5f-9c74-47d2-a345-dd6f5eb4e7c8","title":"HKTL - SharpSuccessor Privilege Escalation Tool Execution","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-06-06","modified":null,"description":"Detects the execution of SharpSuccessor, a tool used to exploit the BadSuccessor attack for privilege escalation in WinServer 2025 Active Directory environments.\nSuccessful usage of this tool can let the attackers gain the domain admin privileges by exploiting the BadSuccessor vulnerability.\n","references":["https://github.com/logangoins/SharpSuccessor"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1068"],"path":"rules/windows/process_creation/proc_creation_win_hktl_sharpsuccessor_execution.yml","techniques":["T1068"],"cves":[]},{"id":"39b64854-5497-4b57-a448-40977b8c9679","title":"Malicious Driver Load By Name","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-10-03","modified":"2023-12-02","description":"Detects loading of known malicious drivers via the file name of the drivers.","references":["https://loldrivers.io/"],"logsource":{"product":"windows","category":"driver_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003","attack.t1068"],"path":"rules/windows/driver_load/driver_load_win_mal_drivers_names.yml","techniques":["T1543.003","T1068"],"cves":[]},{"id":"3be82d5d-09fe-4d6a-a275-0d40d234d324","title":"InstallerFileTakeOver LPE CVE-2021-41379 File Create Event","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-11-22","modified":"2022-12-25","description":"Detects signs of the exploitation of LPE CVE-2021-41379 that include an msiexec process that creates an elevation_service.exe file","references":["https://web.archive.org/web/20220421061949/https://github.com/klinix5/InstallerFileTakeOver","https://www.zerodayinitiative.com/advisories/ZDI-21-1308/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.t1068","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-41379/file_event_win_cve_2021_41379_msi_lpe.yml","techniques":["T1068"],"cves":[]},{"id":"474b415a-8b3d-4e6a-9f12-0d5c8a7b6e94","title":"Linux AF_ALG Socket Creation - Kernel Crypto API Exploit Indicator","author":"Gene Kazimiarovich","status":"experimental","level":"high","date":"2026-04-30","modified":null,"description":"Detects creation of AF_ALG (Address Family 38) sockets via the socket() syscall.\nAF_ALG is the Linux kernel crypto API interface. It is exploited in CVE-2026-31431\nto achieve local privilege escalation via a buffer overflow in the AF_ALG AEAD\nsplice path that corrupts the page cache of SUID binaries.\nLegitimate AF_ALG usage is rare and confined to specific crypto utilities and VPN\ndaemons using non-default kernel offload configurations.\n","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-31431","https://man7.org/linux/man-pages/man2/socket.2.html","https://www.kernel.org/doc/html/latest/crypto/userspace-if.html","https://xint.io/blog/copy-fail-linux-distributions","https://github.com/theori-io/copy-fail-CVE-2026-31431","https://github.com/torvalds/linux/blob/81d6f7807536a0436dfada07e9292e3702d2bed4/include/linux/socket.h#L245"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.privilege-escalation","attack.t1068","detection.emerging-threats","cve.2026-31431"],"path":"rules-emerging-threats/2026/Exploits/CVE-2026-31431/lnx_auditd_exploit_cve_2026_31431_af_alg_socket_creation.yml","techniques":["T1068"],"cves":["CVE-2026-31431"]},{"id":"474b415a-d917-4f3b-8c62-9e1a0d5f7b48","title":"Authencesn Crypto Module Load via Modprobe - Copy-Fail Indicator","author":"Gene Kazimiarovich","status":"experimental","level":"high","date":"2026-05-09","modified":null,"description":"Detects kernel auto-loading of the authencesn crypto module via modprobe\nThis occurs when user-space code creates an AF_ALG socket and binds the authencesn AEAD cipher\n(e.g., authencesn(hmac(sha256),cbc(aes))). The kernel invokes modprobe to load the\ncrypto module. This is a key indicator of CVE-2026-31431 (Copy Fail) exploitation,\nwhere the authencesn cipher is used to trigger a buffer overflow in the AF_ALG AEAD splice path,\ncorrupting the page cache of SUID binaries for local privilege escalation.\n\nOn Linux systems, modprobe is typically a symlink to kmod, so the process image will be /usr/bin/kmod (or /bin/kmod)\nwith 'modprobe' appearing in the command line.\n","references":["https://www.linkedin.com/posts/stamatis-chatzimangou_copyfail-kql-activity-7455582422215114752-S4RW/","https://www.splunk.com/en_us/blog/security/detecting-copy-fail-cve-2026-31431-phenomenal-power-itty-bitty-script.html","https://nvd.nist.gov/vuln/detail/CVE-2026-31431","https://man7.org/linux/man-pages/man8/modprobe.8.html","https://www.kernel.org/doc/html/latest/crypto/userspace-if.html"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1068","attack.persistence","attack.t1547.006","detection.emerging-threats","cve.2026-31431"],"path":"rules-emerging-threats/2026/Exploits/CVE-2026-31431/proc_creation_lnx_exploit_cve_2026_31431_copyfail.yml","techniques":["T1068","T1547.006"],"cves":["CVE-2026-31431"]},{"id":"48d91a3a-2363-43ba-a456-ca71ac3da5c2","title":"Audit CVE Event","author":"Florian Roth (Nextron Systems), Zach Mathis","status":"test","level":"critical","date":"2020-01-15","modified":"2022-10-22","description":"Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited.\nMS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability.\nUnfortunately, that is about the only instance of CVEs being written to this log.\n","references":["https://twitter.com/VM_vivisector/status/1217190929330655232","https://twitter.com/DidierStevens/status/1217533958096924676","https://twitter.com/FlemmingRiis/status/1217147415482060800","https://www.youtube.com/watch?v=ebmW42YYveI","https://nullsec.us/windows-event-log-audit-cve/"],"logsource":{"product":"windows","service":"application"},"tags":["attack.execution","attack.stealth","attack.t1203","attack.privilege-escalation","attack.t1068","attack.t1211","attack.credential-access","attack.t1212","attack.lateral-movement","attack.t1210","attack.impact","attack.t1499.004"],"path":"rules/windows/builtin/application/microsoft-windows_audit_cve/win_audit_cve.yml","techniques":["T1203","T1068","T1211","T1212","T1210","T1499.004"],"cves":[]},{"id":"6d1058a4-407e-4f3a-a144-1968c11dc5c3","title":"Suspicious Sysmon as Execution Parent","author":"Florian Roth (Nextron Systems), Tim Shelton (fp werfault)","status":"test","level":"high","date":"2022-11-10","modified":"2025-07-04","description":"Detects suspicious process executions in which Sysmon itself is the parent of a process, which could be a sign of exploitation (e.g. CVE-2022-41120)","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41120","https://twitter.com/filip_dragovic/status/1590052248260055041","https://twitter.com/filip_dragovic/status/1590104354727436290"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1068","cve.2022-41120","detection.emerging-threats"],"path":"rules-emerging-threats/2022/Exploits/CVE-2022-41120/proc_creation_win_exploit_cve_2022_41120_sysmon_eop.yml","techniques":["T1068"],"cves":["CVE-2022-41120"]},{"id":"6eea1bf6-f8d2-488a-a742-e6ef6c1b67db","title":"OMIGOD SCX RunAsProvider ExecuteScript","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC","status":"test","level":"high","date":"2021-10-15","modified":"2022-10-05","description":"Rule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell.\nScript being executed gets created as a temp file in /tmp folder with a scx* prefix.\nThen it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/.\nThe file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including\nMicrosoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.\n","references":["https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure","https://github.com/Azure/Azure-Sentinel/pull/3059"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.privilege-escalation","attack.initial-access","attack.execution","attack.t1068","attack.t1190","attack.t1203"],"path":"rules/linux/process_creation/proc_creation_lnx_omigod_scx_runasprovider_executescript.yml","techniques":["T1068","T1190","T1203"],"cves":[]},{"id":"72cd00d6-490c-4650-86ff-1d11f491daa1","title":"Vulnerable Driver Load By Name","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2022-10-03","modified":"2023-12-02","description":"Detects the load of known vulnerable drivers via the file name of the drivers.","references":["https://loldrivers.io/"],"logsource":{"product":"windows","category":"driver_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003","attack.t1068"],"path":"rules/windows/driver_load/driver_load_win_vuln_drivers_names.yml","techniques":["T1543.003","T1068"],"cves":[]},{"id":"7aaaf4b8-e47c-4295-92ee-6ed40a6f60c8","title":"Vulnerable Driver Load","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-18","modified":"2023-12-02","description":"Detects loading of known vulnerable drivers via their hash.","references":["https://loldrivers.io/"],"logsource":{"product":"windows","category":"driver_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003","attack.t1068"],"path":"rules/windows/driver_load/driver_load_win_vuln_drivers.yml","techniques":["T1543.003","T1068"],"cves":[]},{"id":"7ba05b43-adad-4c02-b5e9-c8c35cdf9fa8","title":"Potential Nimbuspwn Exploit CVE-2022-29799 and CVE-2022-27800","author":"Bhabesh Raj","status":"test","level":"high","date":"2022-05-04","modified":"2025-11-03","description":"Detects potential exploitation attempts of Nimbuspwn vulnerabilities CVE-2022-29799 and CVE-2022-27800 in Linux systems.\n","references":["https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/","https://github.com/Immersive-Labs-Sec/nimbuspwn"],"logsource":{"product":"linux"},"tags":["attack.privilege-escalation","attack.t1068","detection.emerging-threats","cve.2022-29799","cve.2022-27800"],"path":"rules-emerging-threats/2022/Exploits/CVE-2022-29799/lnx_exploit_cve_2022_27999_cve_2022_27800.yml","techniques":["T1068"],"cves":["CVE-2022-29799","CVE-2022-27800"]},{"id":"7fcc54cb-f27d-4684-84b7-436af096f858","title":"Sudo Privilege Escalation CVE-2019-14287 - Builtin","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2019-10-15","modified":"2022-11-26","description":"Detects users trying to exploit sudo vulnerability reported in CVE-2019-14287","references":["https://www.openwall.com/lists/oss-security/2019/10/14/1","https://access.redhat.com/security/cve/cve-2019-14287","https://twitter.com/matthieugarin/status/1183970598210412546"],"logsource":{"product":"linux","service":"sudo"},"tags":["attack.privilege-escalation","attack.t1068","attack.t1548.003","cve.2019-14287","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Exploits/CVE-2019-14287/lnx_sudo_exploit_cve_2019_14287.yml","techniques":["T1068","T1548.003"],"cves":["CVE-2019-14287"]},{"id":"8a7e90c5-fe6e-45dc-889e-057fe4378bd9","title":"HackTool - SysmonEOP Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2022-12-04","modified":"2024-11-23","description":"Detects the execution of the PoC that can be used to exploit Sysmon CVE-2022-41120","references":["https://github.com/Wh04m1001/SysmonEoP"],"logsource":{"product":"windows","category":"process_creation"},"tags":["cve.2022-41120","attack.t1068","attack.privilege-escalation"],"path":"rules/windows/process_creation/proc_creation_win_hktl_sysmoneop.yml","techniques":["T1068"],"cves":["CVE-2022-41120"]},{"id":"a05baa88-e922-4001-bc4d-8738135f27de","title":"Process Monitor Driver Creation By Non-Sysinternals Binary","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-05","modified":"2026-06-29","description":"Detects creation of the Process Monitor driver by processes other than Process Monitor (procmon) itself.","references":["Internal Research"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1068"],"path":"rules/windows/file/file_event/file_event_win_sysinternals_procmon_driver_susp_creation.yml","techniques":["T1068"],"cves":[]},{"id":"ab6b1a39-a9ee-4ab4-b075-e83acf6e346b","title":"OMIGOD HTTP No Authentication RCE - CVE-2021-38647","author":"Nate Guagenti (neu5ron)","status":"stable","level":"high","date":"2021-09-20","modified":"2025-11-03","description":"Detects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request.\nVerify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP).\nWithin the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.\n","references":["https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure","https://twitter.com/neu5ron/status/1438987292971053057?s=20"],"logsource":{"product":"zeek","service":"http"},"tags":["attack.privilege-escalation","attack.initial-access","attack.execution","attack.lateral-movement","attack.t1068","attack.t1190","attack.t1203","attack.t1021.006","attack.t1210","detection.emerging-threats","cve.2021-38647"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-38647/zeek_http_exploit_cve_2021_38647_omigod_no_auth_rce.yml","techniques":["T1068","T1190","T1203","T1021.006","T1210"],"cves":["CVE-2021-38647"]},{"id":"af8bbce4-f751-46b4-8d91-82a33a736f61","title":"Potential CVE-2021-41379 Exploitation Attempt","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-11-22","modified":"2024-12-01","description":"Detects potential exploitation attempts of CVE-2021-41379 (InstallerFileTakeOver), a local privilege escalation (LPE) vulnerability where the attacker spawns a \"cmd.exe\" process as a child of Microsoft Edge elevation service \"elevation_service\" with \"LOCAL_SYSTEM\" rights","references":["https://web.archive.org/web/20220421061949/https://github.com/klinix5/InstallerFileTakeOver","https://www.bleepingcomputer.com/news/microsoft/new-windows-zero-day-with-public-exploit-lets-you-become-an-admin/","https://www.zerodayinitiative.com/advisories/ZDI-21-1308/","https://www.logpoint.com/en/blog/detecting-privilege-escalation-zero-day-cve-2021-41379/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1068","cve.2021-41379","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-41379/proc_creation_win_exploit_cve_2021_41379.yml","techniques":["T1068"],"cves":["CVE-2021-41379"]},{"id":"c01f7bd6-0c1d-47aa-9c61-187b91273a16","title":"Potential SystemNightmare Exploitation Attempt","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-08-11","modified":"2023-02-04","description":"Detects an exploitation attempt of SystemNightmare in order to obtain a shell as LOCAL_SYSTEM","references":["https://github.com/GossiTheDog/SystemNightmare"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1068","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/SystemNightmare-Exploit/proc_creation_win_exploit_other_systemnightmare.yml","techniques":["T1068"],"cves":[]},{"id":"dcdbc940-0bff-46b2-95f3-2d73f848e33b","title":"Suspicious Spool Service Child Process","author":"Justin C. (@endisphotic), @dreadphones (detection), Thomas Patzke (Sigma rule)","status":"test","level":"high","date":"2021-07-11","modified":"2024-12-01","description":"Detects suspicious print spool service (spoolsv.exe) child processes.","references":["https://github.com/microsoft/Microsoft-365-Defender-Hunting-Queries/blob/efa17a600b43c897b4b7463cc8541daa1987eeb4/Exploits/Print%20Spooler%20RCE/Suspicious%20Spoolsv%20Child%20Process.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1203","attack.privilege-escalation","attack.t1068"],"path":"rules/windows/process_creation/proc_creation_win_spoolsv_susp_child_processes.yml","techniques":["T1203","T1068"],"cves":[]},{"id":"dd7876d8-0f09-11eb-adc1-0242ac120002","title":"Potential Zerologon (CVE-2020-1472) Exploitation","author":"Aleksandr Akhremchik, @aleqs4ndr, ocsd.community","status":"test","level":"high","date":"2020-10-15","modified":"2023-12-15","description":"Detects potential Netlogon Elevation of Privilege Vulnerability aka Zerologon (CVE-2020-1472)","references":["https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472","https://www.logpoint.com/en/blog/detecting-zerologon-vulnerability-in-logpoint/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.t1068","cve.2020-1472"],"path":"rules-placeholder/windows/builtin/security/win_security_exploit_cve_2020_1472.yml","techniques":["T1068"],"cves":["CVE-2020-1472"]},{"id":"de46c52b-0bf8-4936-a327-aace94f94ac6","title":"Process Explorer Driver Creation By Non-Sysinternals Binary","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2023-05-05","modified":"2026-06-29","description":"Detects creation of the Process Explorer drivers by processes other than Process Explorer (procexp) itself.\nHack tools or malware may use the Process Explorer driver to elevate privileges, drops it to disk for a few moments, runs a service using that driver and removes it afterwards.\n","references":["https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer","https://github.com/Yaxser/Backstab","https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks","https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1068"],"path":"rules/windows/file/file_event/file_event_win_sysinternals_procexp_driver_susp_creation.yml","techniques":["T1068"],"cves":[]},{"id":"f2bed782-994e-4f40-9cd5-518198cb3fba","title":"Linux Sudo Chroot Execution","author":"Swachchhanda Shrawn Poudel (Nextron Systems)","status":"experimental","level":"low","date":"2025-10-02","modified":null,"description":"Detects the execution of 'sudo' command with '--chroot' option, which is used to change the root directory for command execution.\nAttackers may use this technique to evade detection and execute commands in a modified environment.\nThis can be part of a privilege escalation strategy, as it allows the execution of commands with elevated privileges in a controlled environment as seen in CVE-2025-32463.\nWhile investigating, look out for unusual or unexpected use of 'sudo --chroot' in conjunction with other commands or scripts such as execution from temporary directories or unusual user accounts.\n","references":["https://github.com/kh4sh3i/CVE-2025-32463/blob/81bb430f84fa2089224733c3ed4bfa434c197ad4/exploit.sh"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1068"],"path":"rules/linux/process_creation/proc_creation_lnx_chroot_execution.yml","techniques":["T1068"],"cves":[]},{"id":"f74107df-b6c6-4e80-bf00-4170b658162b","title":"Sudo Privilege Escalation CVE-2019-14287","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-10-15","modified":"2022-10-05","description":"Detects users trying to exploit sudo vulnerability reported in CVE-2019-14287","references":["https://www.openwall.com/lists/oss-security/2019/10/14/1","https://access.redhat.com/security/cve/cve-2019-14287","https://twitter.com/matthieugarin/status/1183970598210412546"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1068","attack.t1548.003","cve.2019-14287","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Exploits/CVE-2019-14287/proc_creation_lnx_exploit_cve_2019_14287.yml","techniques":["T1068","T1548.003"],"cves":["CVE-2019-14287"]}],"kev_cves":[{"cveID":"CVE-2025-54309","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-25257","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-47812","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-54085","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-33538","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-32030","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-4632","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-12987","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-32709","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-32706","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-32701","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-30400","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-44221","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-1976","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-53197","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-21590","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-24993","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-25181","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-22225","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-4885","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-20118","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-49035","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-0111","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-41710","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-21418","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-21391","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-0994","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-53104","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-29059","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-24085","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-21335","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-21334","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-21333","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-55591","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-12686","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-41713","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-37085","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-22948","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-38080","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2024-4577","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-30051","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-20273","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-28229","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-29256","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-28252","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-47966","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-21674","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-41073","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-41125","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-41033","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-37969","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-22047","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-4034","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2014-0546","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-26904","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-21919","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-22718","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-24521","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-21999","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-20708","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-41379","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-36934","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2020-0787","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-40449","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2020-0069","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2019-0211","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-33739","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2020-1472","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-22900","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}