Techniques › T1068
T1068 Exploitation for Privilege Escalation
privilege escalation — Containers, Linux, macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
31
Sigma rules tagged attack.t1068
69
KEV CVEs mapped here
<p>Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.</p><p>When initially gaining access to a system, an adversary may be operating within a lower privileged process which will prevent them from accessing certain resources on the system. Vulnerabilities may exist, usually in operating system components and software commonly running at higher permissions, that can be exploited to gain higher levels of access on the system. This could enable someone to move from unprivileged or user level permissions to SYSTEM or root permissions depending on the component that is vulnerable. This could also enable an adversary to move from a virtualized environment, such as within a virtual machine or container, onto the underlying host. This may be a necessary step for an adversary compromising an endpoint system that has been properly configured and limits other privilege escalation methods.</p><p>Adversaries may bring a signed vulnerable driver onto a compromised machine so that they can exploit the vulnerability to execute code in kernel mode. This process is sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Adversaries may include the vulnerable driver with files delivered during Initial Access or download it to a compromised system via Ingress Tool Transfer or Lateral Tool Transfer.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2025-54309 | CrushFTP CrushFTP | exploitation technique | Mapped | 2025-07-22 |
| CVE-2025-25257 | Fortinet FortiWeb | exploitation technique | Mapped | 2025-07-18 |
| CVE-2025-47812 | Wing FTP Server Wing FTP Server | exploitation technique | Mapped | 2025-07-14 |
| CVE-2024-54085 | AMI MegaRAC SPx | exploitation technique | Mapped | 2025-06-25 |
| CVE-2023-33538 | TP-Link Multiple Routers | exploitation technique | Mapped | 2025-06-16 |
| CVE-2021-32030 | ASUS Routers | exploitation technique | Mapped | 2025-06-02 |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | exploitation technique | Mapped | 2025-05-22 |
| CVE-2024-12987 | DrayTek Vigor Routers | exploitation technique | Mapped | 2025-05-15 |
| CVE-2025-32709 | Microsoft Windows | exploitation technique | Mapped | 2025-05-13 |
| CVE-2025-32706 | Microsoft Windows | exploitation technique | Mapped | 2025-05-13 |
| CVE-2025-32701 | Microsoft Windows | exploitation technique | Mapped | 2025-05-13 |
| CVE-2025-30400 | Microsoft Windows | exploitation technique | Mapped | 2025-05-13 |
| CVE-2023-44221 | SonicWall SMA100 Appliances | exploitation technique | Mapped | 2025-05-01 |
| CVE-2025-1976 | Broadcom Brocade Fabric OS | exploitation technique | Mapped | 2025-04-28 |
| CVE-2024-53197 | Linux Kernel | exploitation technique | Mapped | 2025-04-09 |
| CVE-2025-21590 | Juniper Junos OS | exploitation technique | Mapped | 2025-03-13 |
| CVE-2025-24993 | Microsoft Windows | exploitation technique | Mapped | 2025-03-11 |
| CVE-2025-25181 | Advantive VeraCore | exploitation technique | Mapped | 2025-03-10 |
| CVE-2025-22225 | VMware ESXi | exploitation technique | Mapped | 2025-03-04 |
| CVE-2024-4885 | Progress WhatsUp Gold | exploitation technique | Mapped | 2025-03-03 |
| CVE-2023-20118 | Cisco Small Business RV Series Routers | exploitation technique | Mapped | 2025-03-03 |
| CVE-2024-49035 | Microsoft Partner Center | exploitation technique | Mapped | 2025-02-25 |
| CVE-2025-0111 | Palo Alto Networks PAN-OS | exploitation technique | Mapped | 2025-02-20 |
| CVE-2024-41710 | Mitel SIP Phones | exploitation technique | Mapped | 2025-02-12 |
| CVE-2025-21418 | Microsoft Windows | exploitation technique | Mapped | 2025-02-11 |
| CVE-2025-21391 | Microsoft Windows | exploitation technique | Mapped | 2025-02-11 |
| CVE-2025-0994 | Trimble Cityworks | exploitation technique | Mapped | 2025-02-07 |
| CVE-2024-53104 | Linux Kernel | exploitation technique | Mapped | 2025-02-05 |
| CVE-2024-29059 | Microsoft .NET Framework | exploitation technique | Mapped | 2025-02-04 |
| CVE-2025-24085 | Apple Multiple Products | exploitation technique | Mapped | 2025-01-29 |
| CVE-2025-21335 | Microsoft Windows | exploitation technique | Mapped | 2025-01-14 |
| CVE-2025-21334 | Microsoft Windows | exploitation technique | Mapped | 2025-01-14 |
| CVE-2025-21333 | Microsoft Windows | exploitation technique | Mapped | 2025-01-14 |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | exploitation technique | Mapped | 2025-01-14 |
| CVE-2024-12686 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) | exploitation technique | Mapped | 2025-01-13 |
| CVE-2024-41713 | Mitel MiCollab | exploitation technique | Mapped | 2025-01-07 |
| CVE-2024-37085 | VMware ESXi | primary impact | Mapped | 2024-07-30 |
| CVE-2022-22948 | VMware vCenter Server | secondary impact | Mapped | 2024-07-17 |
| CVE-2024-38080 | Microsoft Windows | primary impact | Mapped | 2024-07-09 |
| CVE-2024-4577 | PHP Group PHP | secondary impact | Mapped | 2024-06-12 |
| CVE-2024-30051 | Microsoft DWM Core Library | primary impact | Mapped | 2024-05-14 |
| CVE-2023-20273 | Cisco Cisco IOS XE Web UI | primary impact | Mapped | 2023-10-23 |
| CVE-2023-28229 | Microsoft Windows CNG Key Isolation Service | primary impact | Mapped | 2023-10-04 |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | primary impact | Mapped | 2023-07-07 |
| CVE-2023-28252 | Microsoft Windows | primary impact | Mapped | 2023-04-11 |
| CVE-2022-47966 | Zoho ManageEngine | primary impact | Mapped | 2023-01-23 |
| CVE-2023-21674 | Microsoft Windows | primary impact | Mapped | 2023-01-10 |
| CVE-2022-41073 | Microsoft Windows | primary impact | Mapped | 2022-11-08 |
| CVE-2022-41125 | Microsoft Windows | primary impact | Mapped | 2022-11-08 |
| CVE-2022-41033 | Microsoft Windows COM+ Event System Service | primary impact | Mapped | 2022-10-11 |
| CVE-2022-37969 | Microsoft Windows | primary impact | Mapped | 2022-09-14 |
| CVE-2022-22047 | Microsoft Windows | primary impact | Mapped | 2022-07-12 |
| CVE-2021-4034 | Red Hat Polkit | exploitation technique | Mapped | 2022-06-27 |
| CVE-2014-0546 | Adobe Reader and Acrobat | primary impact | Mapped | 2022-05-25 |
| CVE-2022-26904 | Microsoft Windows | primary impact | Mapped | 2022-04-25 |
| CVE-2022-21919 | Microsoft Windows | primary impact | Mapped | 2022-04-25 |
| CVE-2022-22718 | Microsoft Windows | primary impact | Mapped | 2022-04-19 |
| CVE-2022-24521 | Microsoft Windows | primary impact | Mapped | 2022-04-13 |
| CVE-2022-21999 | Microsoft Windows | primary impact | Mapped | 2022-03-25 |
| CVE-2022-20708 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | primary impact | Mapped | 2022-03-03 |
| CVE-2021-41379 | Microsoft Windows | primary impact | Mapped | 2022-03-03 |
| CVE-2021-36934 | Microsoft Windows | primary impact | Mapped | 2022-02-10 |
| CVE-2020-0787 | Microsoft Windows | exploitation technique | Mapped | 2022-01-28 |
| CVE-2021-40449 | Microsoft Windows | primary impact | Mapped | 2021-11-17 |
| CVE-2020-0069 | MediaTek Multiple Chipsets | exploitation technique | Mapped | 2021-11-03 |
| CVE-2019-0211 | Apache HTTP Server | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-33739 | Microsoft Windows | primary impact | Mapped | 2021-11-03 |
| CVE-2020-1472 | Microsoft Netlogon | primary impact | Mapped | 2021-11-03 |
| CVE-2021-22900 | Ivanti Pulse Connect Secure | primary impact | Mapped | 2021-11-03 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0514 Detection Strategy for Exploitation for Privilege Escalation v1.0
AN1419 WindowsDetects exploitation attempts targeting vulnerable kernel drivers or OS components, often followed by unusual process or token behavior.Tunable:
DriverNamePatternTimeWindowParentProcessPathAN1420 LinuxDetects escalation via vulnerable setuid binaries or kernel modules, often chained with unusual access to /proc/kallsyms or /dev/kmem.Tunable:SetUIDBinaryListTimeWindowEffectiveUIDThresholdAN1421 macOSDetects use of vulnerable kernel extensions or entitlements abused via setuid or AppleScript injection chains.Tunable:EntitlementListTimeWindowAN1422 ContainersDetects container breakout behavior via exploitation (e.g., DirtyPipe, CVE-2022-0847), followed by host OS interaction or escalated capability assignment.Tunable:NamespaceEscapePatternTimeWindow
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1068
Author: Florian Roth (Nextron Systems)
· 2019-11-20 (modified 2024-12-01) · logsource: product=windows category=process_creation · 02e0b2ea-a597-428e-b04a-af6a1a403e5c
Detects an exploitation attempt in which the UAC consent dialogue is used to invoke an Internet Explorer process running as LOCAL_SYSTEM
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-08-18 (modified 2023-12-02) · logsource: product=windows category=driver_load · 05296024-fe8a-4baf-8f3d-9a5f5624ceb2
Detects loading of known malicious drivers via their hash.
Author: Florian Roth (Nextron Systems)
· 2021-10-09 (modified 2022-12-25) · logsource: product=linux service=auditd · 071d5e5a-9cef-47ec-bc4e-a42e34d8d0ed
Detects command line parameter very often used with coin miners
Author: Nisarg Suthar
· 2025-08-01 · logsource: product=windows category=process_creation · 0fdc7c7f-c690-4217-9ae3-31f5156eed72
Detects suspicious child processes created by CrushFTP. It could be an indication of exploitation of a RCE vulnerability such as CVE-2025-54309.
Author: Swachchhanda Shrawn Poudel (Nextron Systems)
· 2025-10-02 (modified 2026-03-31) · logsource: product=linux category=file_event · 10ac0730-c24e-4f4c-81f8-b13a1ac95a1d
Detects the creation of nsswitch.conf files in non-standard directories, which may indicate exploitation of CVE-2025-32463.
This vulnerability requires an attacker to create a nsswitch.conf in a directory that will be used during sudo chroot operations.
When sudo executes, it loads malicious shared libraries from user-controlled locations within the chroot environment,
potentially leading to arbitrary code execution and privilege escalation.
Author: @eyezuhk Isaac Fernandes
· 2025-02-19 · logsource: product=windows category=image_load · 17ce9373-2163-4a2c-90ba-f91e9ef7a8c1
Detects potentially suspicious loading of "ksproxy.ax", which may indicate an attempt to exploit CVE-2024-35250.
Author: Florian Roth (Nextron Systems)
· 2017-03-01 (modified 2025-03-17) · logsource: product=linux · 18b042f0-2ecd-4b6e-9f8d-aa7a7e7de781
Detects buffer overflow attempts in Unix system log files
Author: Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro
· 2019-11-15 (modified 2021-11-27) · logsource: product=windows category=process_creation · 1c373b6d-76ce-4553-997d-8c1da9a6b5f5
Detects exploitation attempt of privilege escalation vulnerability via SetupComplete.cmd and PartnerSetupComplete.cmd described in CVE-2019-1378
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
· 2021-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · 21541900-27a9-4454-9c4c-3f0a4240344a
Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell.
SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including
Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-06-06 · logsource: product=windows category=process_creation · 38a1ac5f-9c74-47d2-a345-dd6f5eb4e7c8
Detects the execution of SharpSuccessor, a tool used to exploit the BadSuccessor attack for privilege escalation in WinServer 2025 Active Directory environments.
Successful usage of this tool can let the attackers gain the domain admin privileges by exploiting the BadSuccessor vulnerability.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-10-03 (modified 2023-12-02) · logsource: product=windows category=driver_load · 39b64854-5497-4b57-a448-40977b8c9679
Detects loading of known malicious drivers via the file name of the drivers.
Author: Florian Roth (Nextron Systems)
· 2021-11-22 (modified 2022-12-25) · logsource: product=windows category=file_event · 3be82d5d-09fe-4d6a-a275-0d40d234d324
Detects signs of the exploitation of LPE CVE-2021-41379 that include an msiexec process that creates an elevation_service.exe file
Author: Gene Kazimiarovich
· 2026-04-30 · logsource: product=linux service=auditd · 474b415a-8b3d-4e6a-9f12-0d5c8a7b6e94
Detects creation of AF_ALG (Address Family 38) sockets via the socket() syscall.
AF_ALG is the Linux kernel crypto API interface. It is exploited in CVE-2026-31431
to achieve local privilege escalation via a buffer overflow in the AF_ALG AEAD
splice path that corrupts the page cache of SUID binaries.
Legitimate AF_ALG usage is rare and confined to specific crypto utilities and VPN
daemons using non-default kernel offload configurations.
Author: Gene Kazimiarovich
· 2026-05-09 · logsource: product=linux category=process_creation · 474b415a-d917-4f3b-8c62-9e1a0d5f7b48
Detects kernel auto-loading of the authencesn crypto module via modprobe
This occurs when user-space code creates an AF_ALG socket and binds the authencesn AEAD cipher
(e.g., authencesn(hmac(sha256),cbc(aes))). The kernel invokes modprobe to load the
crypto module. This is a key indicator of CVE-2026-31431 (Copy Fail) exploitation,
where the authencesn cipher is used to trigger a buffer overflow in the AF_ALG AEAD splice path,
corrupting the page cache of SUID binaries for local privilege escalation.
On Linux systems, modprobe is typically a symlink to kmod, so the process image will be /usr/bin/kmod (or /bin/kmod)
with 'modprobe' appearing in the command line.
Author: Florian Roth (Nextron Systems), Zach Mathis
· 2020-01-15 (modified 2022-10-22) · logsource: product=windows service=application · 48d91a3a-2363-43ba-a456-ca71ac3da5c2
Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited.
MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability.
Unfortunately, that is about the only instance of CVEs being written to this log.
Author: Florian Roth (Nextron Systems), Tim Shelton (fp werfault)
· 2022-11-10 (modified 2025-07-04) · logsource: product=windows category=process_creation · 6d1058a4-407e-4f3a-a144-1968c11dc5c3
Detects suspicious process executions in which Sysmon itself is the parent of a process, which could be a sign of exploitation (e.g. CVE-2022-41120)
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
· 2021-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · 6eea1bf6-f8d2-488a-a742-e6ef6c1b67db
Rule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell.
Script being executed gets created as a temp file in /tmp folder with a scx* prefix.
Then it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/.
The file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including
Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-10-03 (modified 2023-12-02) · logsource: product=windows category=driver_load · 72cd00d6-490c-4650-86ff-1d11f491daa1
Detects the load of known vulnerable drivers via the file name of the drivers.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-08-18 (modified 2023-12-02) · logsource: product=windows category=driver_load · 7aaaf4b8-e47c-4295-92ee-6ed40a6f60c8
Detects loading of known vulnerable drivers via their hash.
Author: Bhabesh Raj
· 2022-05-04 (modified 2025-11-03) · logsource: product=linux · 7ba05b43-adad-4c02-b5e9-c8c35cdf9fa8
Detects potential exploitation attempts of Nimbuspwn vulnerabilities CVE-2022-29799 and CVE-2022-27800 in Linux systems.
Author: Florian Roth (Nextron Systems)
· 2019-10-15 (modified 2022-11-26) · logsource: product=linux service=sudo · 7fcc54cb-f27d-4684-84b7-436af096f858
Detects users trying to exploit sudo vulnerability reported in CVE-2019-14287
Author: Florian Roth (Nextron Systems)
· 2022-12-04 (modified 2024-11-23) · logsource: product=windows category=process_creation · 8a7e90c5-fe6e-45dc-889e-057fe4378bd9
Detects the execution of the PoC that can be used to exploit Sysmon CVE-2022-41120
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-05-05 (modified 2026-06-29) · logsource: product=windows category=file_event · a05baa88-e922-4001-bc4d-8738135f27de
Detects creation of the Process Monitor driver by processes other than Process Monitor (procmon) itself.
Author: Nate Guagenti (neu5ron)
· 2021-09-20 (modified 2025-11-03) · logsource: product=zeek service=http · ab6b1a39-a9ee-4ab4-b075-e83acf6e346b
Detects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request.
Verify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP).
Within the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.
Author: Florian Roth (Nextron Systems)
· 2021-11-22 (modified 2024-12-01) · logsource: product=windows category=process_creation · af8bbce4-f751-46b4-8d91-82a33a736f61
Detects potential exploitation attempts of CVE-2021-41379 (InstallerFileTakeOver), a local privilege escalation (LPE) vulnerability where the attacker spawns a "cmd.exe" process as a child of Microsoft Edge elevation service "elevation_service" with "LOCAL_SYSTEM" rights
Author: Florian Roth (Nextron Systems)
· 2021-08-11 (modified 2023-02-04) · logsource: product=windows category=process_creation · c01f7bd6-0c1d-47aa-9c61-187b91273a16
Detects an exploitation attempt of SystemNightmare in order to obtain a shell as LOCAL_SYSTEM
Author: Justin C. (@endisphotic), @dreadphones (detection), Thomas Patzke (Sigma rule)
· 2021-07-11 (modified 2024-12-01) · logsource: product=windows category=process_creation · dcdbc940-0bff-46b2-95f3-2d73f848e33b
Detects suspicious print spool service (spoolsv.exe) child processes.
Author: Aleksandr Akhremchik, @aleqs4ndr, ocsd.community
· 2020-10-15 (modified 2023-12-15) · logsource: product=windows service=security · dd7876d8-0f09-11eb-adc1-0242ac120002
Detects potential Netlogon Elevation of Privilege Vulnerability aka Zerologon (CVE-2020-1472)
Author: Florian Roth (Nextron Systems)
· 2023-05-05 (modified 2026-06-29) · logsource: product=windows category=file_event · de46c52b-0bf8-4936-a327-aace94f94ac6
Detects creation of the Process Explorer drivers by processes other than Process Explorer (procexp) itself.
Hack tools or malware may use the Process Explorer driver to elevate privileges, drops it to disk for a few moments, runs a service using that driver and removes it afterwards.
Author: Swachchhanda Shrawn Poudel (Nextron Systems)
· 2025-10-02 · logsource: product=linux category=process_creation · f2bed782-994e-4f40-9cd5-518198cb3fba
Detects the execution of 'sudo' command with '--chroot' option, which is used to change the root directory for command execution.
Attackers may use this technique to evade detection and execute commands in a modified environment.
This can be part of a privilege escalation strategy, as it allows the execution of commands with elevated privileges in a controlled environment as seen in CVE-2025-32463.
While investigating, look out for unusual or unexpected use of 'sudo --chroot' in conjunction with other commands or scripts such as execution from temporary directories or unusual user accounts.
Author: Florian Roth (Nextron Systems)
· 2019-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · f74107df-b6c6-4e80-bf00-4170b658162b
Detects users trying to exploit sudo vulnerability reported in CVE-2019-14287