ATT&CKMatrixPrivilege Escalation

Privilege Escalation

TA0004

Tactic.View on attack.mitre.org

About this tactic

The adversary is trying to gain higher-level permissions.

Privilege Escalation consists of techniques that adversaries use to gain higher-level permissions on a system or network. Adversaries can often enter and explore a network with unprivileged access but require elevated permissions to follow through on their objectives. Common approaches are to take advantage of system weaknesses, misconfigurations, and vulnerabilities. Examples of elevated access include:

* SYSTEM/root level
* local administrator
* user account with admin-like access
* user accounts with access to specific system or perform specific function

These techniques often overlap with Persistence techniques, as OS features that let an adversary persist can execute in an elevated context.

Techniques13

IDNameSub-techniquesExamples
T1037Boot or Logon Initialization Scripts522
T1053Scheduled Task/Job5216
T1055Process Injection12239
T1068Exploitation for Privilege Escalation043
T1078Valid Accounts4149
T1098Account Manipulation745
T1134Access Token Manipulation567
T1484Domain or Tenant Policy Modification220
T1543Create or Modify System Process5198
T1546Event Triggered Execution1881
T1547Boot or Logon Autostart Execution14333
T1548Abuse Elevation Control Mechanism675
T1611Escape to Host05

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.