kevmap

Techniques › T1068

T1068 Exploitation for Privilege Escalation

privilege escalation — Containers, Linux, macOS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
4
analytics
31
Sigma rules tagged attack.t1068
69
KEV CVEs mapped here
<p>Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.</p><p>When initially gaining access to a system, an adversary may be operating within a lower privileged process which will prevent them from accessing certain resources on the system. Vulnerabilities may exist, usually in operating system components and software commonly running at higher permissions, that can be exploited to gain higher levels of access on the system. This could enable someone to move from unprivileged or user level permissions to SYSTEM or root permissions depending on the component that is vulnerable. This could also enable an adversary to move from a virtualized environment, such as within a virtual machine or container, onto the underlying host. This may be a necessary step for an adversary compromising an endpoint system that has been properly configured and limits other privilege escalation methods.</p><p>Adversaries may bring a signed vulnerable driver onto a compromised machine so that they can exploit the vulnerability to execute code in kernel mode. This process is sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Adversaries may include the vulnerable driver with files delivered during Initial Access or download it to a compromised system via Ingress Tool Transfer or Lateral Tool Transfer.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2025-54309CrushFTP CrushFTP exploitation technique Mapped2025-07-22
CVE-2025-25257Fortinet FortiWeb exploitation technique Mapped2025-07-18
CVE-2025-47812Wing FTP Server Wing FTP Server exploitation technique Mapped2025-07-14
CVE-2024-54085AMI MegaRAC SPx exploitation technique Mapped2025-06-25
CVE-2023-33538TP-Link Multiple Routers exploitation technique Mapped2025-06-16
CVE-2021-32030ASUS Routers exploitation technique Mapped2025-06-02
CVE-2025-4632Samsung MagicINFO 9 Server exploitation technique Mapped2025-05-22
CVE-2024-12987DrayTek Vigor Routers exploitation technique Mapped2025-05-15
CVE-2025-32709Microsoft Windows exploitation technique Mapped2025-05-13
CVE-2025-32706Microsoft Windows exploitation technique Mapped2025-05-13
CVE-2025-32701Microsoft Windows exploitation technique Mapped2025-05-13
CVE-2025-30400Microsoft Windows exploitation technique Mapped2025-05-13
CVE-2023-44221SonicWall SMA100 Appliances exploitation technique Mapped2025-05-01
CVE-2025-1976Broadcom Brocade Fabric OS exploitation technique Mapped2025-04-28
CVE-2024-53197Linux Kernel exploitation technique Mapped2025-04-09
CVE-2025-21590Juniper Junos OS exploitation technique Mapped2025-03-13
CVE-2025-24993Microsoft Windows exploitation technique Mapped2025-03-11
CVE-2025-25181Advantive VeraCore exploitation technique Mapped2025-03-10
CVE-2025-22225VMware ESXi exploitation technique Mapped2025-03-04
CVE-2024-4885Progress WhatsUp Gold exploitation technique Mapped2025-03-03
CVE-2023-20118Cisco Small Business RV Series Routers exploitation technique Mapped2025-03-03
CVE-2024-49035Microsoft Partner Center exploitation technique Mapped2025-02-25
CVE-2025-0111Palo Alto Networks PAN-OS exploitation technique Mapped2025-02-20
CVE-2024-41710Mitel SIP Phones exploitation technique Mapped2025-02-12
CVE-2025-21418Microsoft Windows exploitation technique Mapped2025-02-11
CVE-2025-21391Microsoft Windows exploitation technique Mapped2025-02-11
CVE-2025-0994Trimble Cityworks exploitation technique Mapped2025-02-07
CVE-2024-53104Linux Kernel exploitation technique Mapped2025-02-05
CVE-2024-29059Microsoft .NET Framework exploitation technique Mapped2025-02-04
CVE-2025-24085Apple Multiple Products exploitation technique Mapped2025-01-29
CVE-2025-21335Microsoft Windows exploitation technique Mapped2025-01-14
CVE-2025-21334Microsoft Windows exploitation technique Mapped2025-01-14
CVE-2025-21333Microsoft Windows exploitation technique Mapped2025-01-14
CVE-2024-55591Fortinet FortiOS and FortiProxy exploitation technique Mapped2025-01-14
CVE-2024-12686BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) exploitation technique Mapped2025-01-13
CVE-2024-41713Mitel MiCollab exploitation technique Mapped2025-01-07
CVE-2024-37085VMware ESXi primary impact Mapped2024-07-30
CVE-2022-22948VMware vCenter Server secondary impact Mapped2024-07-17
CVE-2024-38080Microsoft Windows primary impact Mapped2024-07-09
CVE-2024-4577PHP Group PHP secondary impact Mapped2024-06-12
CVE-2024-30051Microsoft DWM Core Library primary impact Mapped2024-05-14
CVE-2023-20273Cisco Cisco IOS XE Web UI primary impact Mapped2023-10-23
CVE-2023-28229Microsoft Windows CNG Key Isolation Service primary impact Mapped2023-10-04
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) primary impact Mapped2023-07-07
CVE-2023-28252Microsoft Windows primary impact Mapped2023-04-11
CVE-2022-47966Zoho ManageEngine primary impact Mapped2023-01-23
CVE-2023-21674Microsoft Windows primary impact Mapped2023-01-10
CVE-2022-41073Microsoft Windows primary impact Mapped2022-11-08
CVE-2022-41125Microsoft Windows primary impact Mapped2022-11-08
CVE-2022-41033Microsoft Windows COM+ Event System Service primary impact Mapped2022-10-11
CVE-2022-37969Microsoft Windows primary impact Mapped2022-09-14
CVE-2022-22047Microsoft Windows primary impact Mapped2022-07-12
CVE-2021-4034Red Hat Polkit exploitation technique Mapped2022-06-27
CVE-2014-0546Adobe Reader and Acrobat primary impact Mapped2022-05-25
CVE-2022-26904Microsoft Windows primary impact Mapped2022-04-25
CVE-2022-21919Microsoft Windows primary impact Mapped2022-04-25
CVE-2022-22718Microsoft Windows primary impact Mapped2022-04-19
CVE-2022-24521Microsoft Windows primary impact Mapped2022-04-13
CVE-2022-21999Microsoft Windows primary impact Mapped2022-03-25
CVE-2022-20708Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers primary impact Mapped2022-03-03
CVE-2021-41379Microsoft Windows primary impact Mapped2022-03-03
CVE-2021-36934Microsoft Windows primary impact Mapped2022-02-10
CVE-2020-0787Microsoft Windows exploitation technique Mapped2022-01-28
CVE-2021-40449Microsoft Windows primary impact Mapped2021-11-17
CVE-2020-0069MediaTek Multiple Chipsets exploitation technique Mapped2021-11-03
CVE-2019-0211Apache HTTP Server exploitation technique Mapped2021-11-03
CVE-2021-33739Microsoft Windows primary impact Mapped2021-11-03
CVE-2020-1472Microsoft Netlogon primary impact Mapped2021-11-03
CVE-2021-22900Ivanti Pulse Connect Secure primary impact Mapped2021-11-03

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1068

Author: Florian Roth (Nextron Systems) · 2019-11-20 (modified 2024-12-01) · logsource: product=windows category=process_creation · 02e0b2ea-a597-428e-b04a-af6a1a403e5c
Detects an exploitation attempt in which the UAC consent dialogue is used to invoke an Internet Explorer process running as LOCAL_SYSTEM
Techniques: T1068
CVE tags: CVE-2019-1388
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-08-18 (modified 2023-12-02) · logsource: product=windows category=driver_load · 05296024-fe8a-4baf-8f3d-9a5f5624ceb2
Detects loading of known malicious drivers via their hash.
Techniques: T1543.003T1068
Author: Florian Roth (Nextron Systems) · 2021-10-09 (modified 2022-12-25) · logsource: product=linux service=auditd · 071d5e5a-9cef-47ec-bc4e-a42e34d8d0ed
Detects command line parameter very often used with coin miners
Techniques: T1068
Author: Nisarg Suthar · 2025-08-01 · logsource: product=windows category=process_creation · 0fdc7c7f-c690-4217-9ae3-31f5156eed72
Detects suspicious child processes created by CrushFTP. It could be an indication of exploitation of a RCE vulnerability such as CVE-2025-54309.
CVE tags: CVE-2025-54309
Author: Swachchhanda Shrawn Poudel (Nextron Systems) · 2025-10-02 (modified 2026-03-31) · logsource: product=linux category=file_event · 10ac0730-c24e-4f4c-81f8-b13a1ac95a1d
Detects the creation of nsswitch.conf files in non-standard directories, which may indicate exploitation of CVE-2025-32463. This vulnerability requires an attacker to create a nsswitch.conf in a directory that will be used during sudo chroot operations. When sudo executes, it loads malicious shared libraries from user-controlled locations within the chroot environment, potentially leading to arbitrary code execution and privilege escalation.
Techniques: T1068
CVE tags: CVE-2025-32463
Author: @eyezuhk Isaac Fernandes · 2025-02-19 · logsource: product=windows category=image_load · 17ce9373-2163-4a2c-90ba-f91e9ef7a8c1
Detects potentially suspicious loading of "ksproxy.ax", which may indicate an attempt to exploit CVE-2024-35250.
Techniques: T1068
CVE tags: CVE-2024-35250
Author: Florian Roth (Nextron Systems) · 2017-03-01 (modified 2025-03-17) · logsource: product=linux · 18b042f0-2ecd-4b6e-9f8d-aa7a7e7de781
Detects buffer overflow attempts in Unix system log files
Techniques: T1068
Author: Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro · 2019-11-15 (modified 2021-11-27) · logsource: product=windows category=process_creation · 1c373b6d-76ce-4553-997d-8c1da9a6b5f5
Detects exploitation attempt of privilege escalation vulnerability via SetupComplete.cmd and PartnerSetupComplete.cmd described in CVE-2019-1378
CVE tags: CVE-2019-1378
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC · 2021-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · 21541900-27a9-4454-9c4c-3f0a4240344a
Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
Techniques: T1068T1190T1203
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-06-06 · logsource: product=windows category=process_creation · 38a1ac5f-9c74-47d2-a345-dd6f5eb4e7c8
Detects the execution of SharpSuccessor, a tool used to exploit the BadSuccessor attack for privilege escalation in WinServer 2025 Active Directory environments. Successful usage of this tool can let the attackers gain the domain admin privileges by exploiting the BadSuccessor vulnerability.
Techniques: T1068
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-10-03 (modified 2023-12-02) · logsource: product=windows category=driver_load · 39b64854-5497-4b57-a448-40977b8c9679
Detects loading of known malicious drivers via the file name of the drivers.
Techniques: T1543.003T1068
Author: Florian Roth (Nextron Systems) · 2021-11-22 (modified 2022-12-25) · logsource: product=windows category=file_event · 3be82d5d-09fe-4d6a-a275-0d40d234d324
Detects signs of the exploitation of LPE CVE-2021-41379 that include an msiexec process that creates an elevation_service.exe file
Techniques: T1068
Author: Gene Kazimiarovich · 2026-04-30 · logsource: product=linux service=auditd · 474b415a-8b3d-4e6a-9f12-0d5c8a7b6e94
Detects creation of AF_ALG (Address Family 38) sockets via the socket() syscall. AF_ALG is the Linux kernel crypto API interface. It is exploited in CVE-2026-31431 to achieve local privilege escalation via a buffer overflow in the AF_ALG AEAD splice path that corrupts the page cache of SUID binaries. Legitimate AF_ALG usage is rare and confined to specific crypto utilities and VPN daemons using non-default kernel offload configurations.
Techniques: T1068
CVE tags: CVE-2026-31431
Author: Gene Kazimiarovich · 2026-05-09 · logsource: product=linux category=process_creation · 474b415a-d917-4f3b-8c62-9e1a0d5f7b48
Detects kernel auto-loading of the authencesn crypto module via modprobe This occurs when user-space code creates an AF_ALG socket and binds the authencesn AEAD cipher (e.g., authencesn(hmac(sha256),cbc(aes))). The kernel invokes modprobe to load the crypto module. This is a key indicator of CVE-2026-31431 (Copy Fail) exploitation, where the authencesn cipher is used to trigger a buffer overflow in the AF_ALG AEAD splice path, corrupting the page cache of SUID binaries for local privilege escalation. On Linux systems, modprobe is typically a symlink to kmod, so the process image will be /usr/bin/kmod (or /bin/kmod) with 'modprobe' appearing in the command line.
Techniques: T1068T1547.006
CVE tags: CVE-2026-31431
Audit CVE Event criticaltest
Author: Florian Roth (Nextron Systems), Zach Mathis · 2020-01-15 (modified 2022-10-22) · logsource: product=windows service=application · 48d91a3a-2363-43ba-a456-ca71ac3da5c2
Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.
Author: Florian Roth (Nextron Systems), Tim Shelton (fp werfault) · 2022-11-10 (modified 2025-07-04) · logsource: product=windows category=process_creation · 6d1058a4-407e-4f3a-a144-1968c11dc5c3
Detects suspicious process executions in which Sysmon itself is the parent of a process, which could be a sign of exploitation (e.g. CVE-2022-41120)
Techniques: T1068
CVE tags: CVE-2022-41120
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC · 2021-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · 6eea1bf6-f8d2-488a-a742-e6ef6c1b67db
Rule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell. Script being executed gets created as a temp file in /tmp folder with a scx* prefix. Then it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/. The file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
Techniques: T1068T1190T1203
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-10-03 (modified 2023-12-02) · logsource: product=windows category=driver_load · 72cd00d6-490c-4650-86ff-1d11f491daa1
Detects the load of known vulnerable drivers via the file name of the drivers.
Techniques: T1543.003T1068
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-08-18 (modified 2023-12-02) · logsource: product=windows category=driver_load · 7aaaf4b8-e47c-4295-92ee-6ed40a6f60c8
Detects loading of known vulnerable drivers via their hash.
Techniques: T1543.003T1068
Author: Bhabesh Raj · 2022-05-04 (modified 2025-11-03) · logsource: product=linux · 7ba05b43-adad-4c02-b5e9-c8c35cdf9fa8
Detects potential exploitation attempts of Nimbuspwn vulnerabilities CVE-2022-29799 and CVE-2022-27800 in Linux systems.
Techniques: T1068
CVE tags: CVE-2022-29799CVE-2022-27800
Author: Florian Roth (Nextron Systems) · 2019-10-15 (modified 2022-11-26) · logsource: product=linux service=sudo · 7fcc54cb-f27d-4684-84b7-436af096f858
Detects users trying to exploit sudo vulnerability reported in CVE-2019-14287
Techniques: T1068T1548.003
CVE tags: CVE-2019-14287
Author: Florian Roth (Nextron Systems) · 2022-12-04 (modified 2024-11-23) · logsource: product=windows category=process_creation · 8a7e90c5-fe6e-45dc-889e-057fe4378bd9
Detects the execution of the PoC that can be used to exploit Sysmon CVE-2022-41120
Techniques: T1068
CVE tags: CVE-2022-41120
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-05-05 (modified 2026-06-29) · logsource: product=windows category=file_event · a05baa88-e922-4001-bc4d-8738135f27de
Detects creation of the Process Monitor driver by processes other than Process Monitor (procmon) itself.
Techniques: T1068
Author: Nate Guagenti (neu5ron) · 2021-09-20 (modified 2025-11-03) · logsource: product=zeek service=http · ab6b1a39-a9ee-4ab4-b075-e83acf6e346b
Detects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request. Verify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP). Within the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.
CVE tags: CVE-2021-38647
Author: Florian Roth (Nextron Systems) · 2021-11-22 (modified 2024-12-01) · logsource: product=windows category=process_creation · af8bbce4-f751-46b4-8d91-82a33a736f61
Detects potential exploitation attempts of CVE-2021-41379 (InstallerFileTakeOver), a local privilege escalation (LPE) vulnerability where the attacker spawns a "cmd.exe" process as a child of Microsoft Edge elevation service "elevation_service" with "LOCAL_SYSTEM" rights
Techniques: T1068
CVE tags: CVE-2021-41379
Author: Florian Roth (Nextron Systems) · 2021-08-11 (modified 2023-02-04) · logsource: product=windows category=process_creation · c01f7bd6-0c1d-47aa-9c61-187b91273a16
Detects an exploitation attempt of SystemNightmare in order to obtain a shell as LOCAL_SYSTEM
Techniques: T1068
Author: Justin C. (@endisphotic), @dreadphones (detection), Thomas Patzke (Sigma rule) · 2021-07-11 (modified 2024-12-01) · logsource: product=windows category=process_creation · dcdbc940-0bff-46b2-95f3-2d73f848e33b
Detects suspicious print spool service (spoolsv.exe) child processes.
Techniques: T1203T1068
Author: Aleksandr Akhremchik, @aleqs4ndr, ocsd.community · 2020-10-15 (modified 2023-12-15) · logsource: product=windows service=security · dd7876d8-0f09-11eb-adc1-0242ac120002
Detects potential Netlogon Elevation of Privilege Vulnerability aka Zerologon (CVE-2020-1472)
Techniques: T1068
CVE tags: CVE-2020-1472
Author: Florian Roth (Nextron Systems) · 2023-05-05 (modified 2026-06-29) · logsource: product=windows category=file_event · de46c52b-0bf8-4936-a327-aace94f94ac6
Detects creation of the Process Explorer drivers by processes other than Process Explorer (procexp) itself. Hack tools or malware may use the Process Explorer driver to elevate privileges, drops it to disk for a few moments, runs a service using that driver and removes it afterwards.
Techniques: T1068
Author: Swachchhanda Shrawn Poudel (Nextron Systems) · 2025-10-02 · logsource: product=linux category=process_creation · f2bed782-994e-4f40-9cd5-518198cb3fba
Detects the execution of 'sudo' command with '--chroot' option, which is used to change the root directory for command execution. Attackers may use this technique to evade detection and execute commands in a modified environment. This can be part of a privilege escalation strategy, as it allows the execution of commands with elevated privileges in a controlled environment as seen in CVE-2025-32463. While investigating, look out for unusual or unexpected use of 'sudo --chroot' in conjunction with other commands or scripts such as execution from temporary directories or unusual user accounts.
Techniques: T1068
Author: Florian Roth (Nextron Systems) · 2019-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · f74107df-b6c6-4e80-bf00-4170b658162b
Detects users trying to exploit sudo vulnerability reported in CVE-2019-14287
Techniques: T1068T1548.003
CVE tags: CVE-2019-14287