Privilege Escalation Detection Rules
The adversary is trying to gain higher-level permissions. Privilege Escalation consists of techniques that adversaries use to gain higher-level permissions on a system or network. Adversaries can often enter and explore a network with unprivileged access but require elevated permissions to follow through on their objectives. Common approaches are to take advantage of system weaknesses, misconfigurations, and vulnerabilities. Examples of elevated access include: * SYSTEM/root level * local administrator * user account with admin-like access * user accounts with access to specific system or perform specific function These techniques often overlap with Persistence techniques, as OS features that let an adversary persist can execute in an elevated context.
df00tech ships 210 production-ready detection rules mapped to the Privilege Escalation tactic (TA0004). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Unlock the full Pro package
Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.
Privilege Escalation detections (210)
- CVE-2008-4250 MS08-067 NetAPI Buffer Overflow Exploitation Attempt (CVE-2008-4250)
- CVE-2012-1854 CVE-2012-1854 - Microsoft VBA Insecure Library Loading (DLL Hijacking)
- CVE-2018-14634 Linux Kernel Integer Overflow in create_elf_tables (CVE-2018-14634)
- CVE-2019-19006 Sangoma FreePBX Remote Admin Authentication Bypass (CVE-2019-19006)
- CVE-2021-30952 CVE-2021-30952: Apple Multiple Products Integer Overflow Exploitation
- CVE-2022-0492 Linux Kernel cgroup v1 release_agent Privilege Escalation (CVE-2022-0492)
- CVE-2022-20775 CVE-2022-20775 — Cisco SD-WAN Path Traversal Exploitation Attempt
- CVE-2023-27351 CVE-2023-27351 - PaperCut NG/MF Improper Authentication Exploitation
- CVE-2023-36424 CVE-2023-36424 - Microsoft Windows Out-of-Bounds Read Exploitation
- CVE-2023-41974 Apple iOS/iPadOS Use-After-Free Exploitation (CVE-2023-41974)
- CVE-2023-43000 Apple Multiple Products Use-After-Free Vulnerability (CVE-2023-43000)
- CVE-2023-52163 Digiever DS-2105 Pro Missing Authorization Exploitation (CVE-2023-52163)
- CVE-2024-26234 CVE-2024-26234 — Windows Proxy Driver Spoofing via Malicious Signed Driver
- CVE-2024-57726 SimpleHelp Missing Authorization Vulnerability (CVE-2024-57726)
- CVE-2025-2746 CVE-2025-2746: Kentico Xperience CMS Authentication Bypass
- CVE-2025-2747 Kentico Xperience CMS Authentication Bypass (CVE-2025-2747)
- CVE-2025-6205 Dassault Systèmes DELMIA Apriso Missing Authorization (CVE-2025-6205)
- CVE-2025-14174 CVE-2025-14174: Google Chromium Out of Bounds Memory Access Exploitation
- CVE-2025-20393 CVE-2025-20393 — Cisco Multiple Products Improper Input Validation (KEV)
- CVE-2025-31277 Apple Multiple Products Buffer Overflow Exploitation (CVE-2025-31277)
- CVE-2025-34026 Versa Concerto Improper Authentication (CVE-2025-34026)
- CVE-2025-34291 CVE-2025-34291: Langflow Origin Validation Error Exploitation
- CVE-2025-40536 SolarWinds Web Help Desk Security Control Bypass (CVE-2025-40536)
- CVE-2025-40602 CVE-2025-40602 - SonicWall SMA1000 Missing Authorization Exploitation
- CVE-2025-41244 CVE-2025-41244 - VMware Aria Operations & VMware Tools Privilege Escalation via Unsafe Actions
- CVE-2025-43510 Apple Multiple Products Improper Locking Vulnerability (CVE-2025-43510)
- CVE-2025-43529 Apple WebKit Use-After-Free Exploitation Attempt (CVE-2025-43529)
- CVE-2025-48703 CVE-2025-48703 - CWP Control Web Panel OS Command Injection
- CVE-2025-60710 Microsoft Windows Link Following Vulnerability (CVE-2025-60710)
- CVE-2025-62215 CVE-2025-62215 Microsoft Windows Race Condition Exploitation
- CVE-2025-62221 CVE-2025-62221 Microsoft Windows Use After Free Exploitation
- CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass (CVE-2026-0257)
- CVE-2026-3910 CVE-2026-3910: Google Chromium V8 Memory Buffer Bounds Violation
- CVE-2026-5281 CVE-2026-5281 — Google Dawn Use-After-Free Exploitation
- CVE-2026-6973 CVE-2026-6973: Ivanti EPMM Improper Input Validation Exploitation
- CVE-2026-20122 Cisco Catalyst SD-WAN Manager Privileged API Abuse (CVE-2026-20122)
- CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20182)
- CVE-2026-20245 Cisco Catalyst SD-WAN Manager Improper Output Encoding Exploitation
- CVE-2026-20700 Apple Multiple Products Buffer Overflow Exploitation (CVE-2026-20700)
- CVE-2026-20805 Microsoft Windows Information Disclosure (CVE-2026-20805)
- CVE-2026-21510 CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure
- CVE-2026-21519 Microsoft Windows Type Confusion Vulnerability (CVE-2026-21519)
- CVE-2026-21525 CVE-2026-21525 - Microsoft Windows NULL Pointer Dereference Exploitation
- CVE-2026-21533 Microsoft Windows Improper Privilege Management (CVE-2026-21533)
- CVE-2026-21643 Fortinet FortiClient EMS SQL Injection Exploitation (CVE-2026-21643)
- CVE-2026-24061 GNU InetUtils Argument Injection Vulnerability (CVE-2026-24061)
- CVE-2026-24423 SmarterMail Missing Authentication for Critical Function (CVE-2026-24423)
- CVE-2026-25108 Soliton FileZen OS Command Injection Exploitation (CVE-2026-25108)
- CVE-2026-31431 Linux Kernel Incorrect Resource Transfer Between Spheres (CVE-2026-31431)
- CVE-2026-32202 CVE-2026-32202 Microsoft Windows Protection Mechanism Failure
- CVE-2026-33017 CVE-2026-33017: Langflow Code Injection Vulnerability
- CVE-2026-33825 CVE-2026-33825 - Microsoft Defender Insufficient Access Control Exploitation
- CVE-2026-34908 CVE-2026-34908 — Ubiquiti UniFi OS Improper Access Control Exploitation
- CVE-2026-35273 Oracle PeopleSoft PeopleTools Missing Authentication for Critical Function (CVE-2026-35273)
- CVE-2026-35616 CVE-2026-35616 — Fortinet FortiClient EMS Improper Access Control Exploitation
- CVE-2026-39987 Marimo Remote Code Execution via Missing Authentication (CVE-2026-39987)
- CVE-2026-41091 Microsoft Defender Link Following Privilege Escalation (CVE-2026-41091)
- CVE-2026-41940 CVE-2026-41940: WebPros cPanel & WHM / WP2 Missing Authentication for Critical Function
- CVE-2026-44179 CVE-2026-44179: XWiki Pro Macros RCE via Excerpt-Include Macro
- CVE-2026-44180 CVE-2026-44180: Jupyter Enterprise Gateway ContainerProcessProxy._enforce_prohibited_ids Bypass
- CVE-2026-44935 Rancher Fleet Cross-Namespace Secret Disclosure via Unvalidated valuesFrom in Helm Deployer (CVE-2026-44935)
- CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Exploitation (CVE-2026-46817)
- CVE-2026-47103 python-statemachine SCXML <data expr> Eval Injection (CVE-2026-47103)
- CVE-2026-47137 CVE-2026-47137 — vm2 Sandbox Escape via nesting:true Bypass (RCE)
- CVE-2026-47140 CVE-2026-47140 — vm2 Builtin Denylist Bypass via process/inspector Leads to Host RCE
- CVE-2026-47208 CVE-2026-47208: vm2 Sandbox Breakout via Promise Species
- CVE-2026-47210 vm2 Sandbox Escape via JSPI-backed Promise .finally() Species Bypass
- CVE-2026-47391 CVE-2026-47391: PraisonAI Unauthenticated A2A LLM eval() Remote Code Execution
- CVE-2026-47392 PraisonAI Sandbox Escape via print.__self__ Builtins Leak in execute_code
- CVE-2026-47410 PraisonAI Platform JWT Hardcoded Secret Key Token Forgery
- CVE-2026-47413 CVE-2026-47413: PraisonAI Platform Unauthorized Workspace Owner Privilege Escalation
- CVE-2026-47724 nebula-mesh API Ownership Check Bypass — Cross-Operator Privilege Escalation
- CVE-2026-47744 Shopper Framework Authorization Bypass and RBAC Privilege Escalation in Team Settings
- CVE-2026-48030 Pheditor OS Command Injection via Unsanitized 'dir' Parameter (CVE-2026-48030)
- CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation (CVE-2026-48172)
- CVE-2026-48749 CVE-2026-48749: Incus Arbitrary File Read/Write via rootfs Symlink in Malicious Image
- CVE-2026-48750 Incus exec-output Symlink Arbitrary File Write on Host (CVE-2026-48750)
- CVE-2026-48751 CVE-2026-48751: Incus Restricted Project Bypass Leading to Arbitrary Command Execution
- CVE-2026-48752 Incus Arbitrary File Read/Write via Malicious Image Template Symlink
- CVE-2026-48753 CVE-2026-48753: Incus S3 Multipart Upload Path Traversal Arbitrary File Write
- CVE-2026-48755 Incus Argument Injection in Backup Compression Algorithm (CVE-2026-48755)
- CVE-2026-48769 CVE-2026-48769: Incus Arbitrary File Write via Trusted Image Hash
- CVE-2026-48907 Widget Factory Joomla Content Editor Improper Access Control (CVE-2026-48907)
- CVE-2026-49252 Deepstream Server Prototype Pollution (CVE-2026-49252)
- CVE-2026-49257 CVE-2026-49257: mcp-pinot Unauthenticated Tool Invocation via Default oauth_enabled=False
- CVE-2026-50545 CVE-2026-50545: Fission Environment CRD PodSpec Injection
- CVE-2026-50551 SiYuan Attribute View Asset Cell Stored XSS to RCE (CVE-2026-50551)
- CVE-2026-50563 Fission Container Executor PodSpec Injection - Node Escape Attempt
- CVE-2026-50564 Fission Environment CRD PodSpec Passthrough Node Escape (CVE-2026-50564)
- CVE-2026-52831 Nuclio Cron Trigger Header/Body Command Injection (CVE-2026-52831)
- CVE-2026-53633 CVE-2026-53633: Vitest Browser Mode API RCE via CDP Proxy and Config Overwrite
- CVE-2026-53753 Crawl4AI AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE
- CVE-2026-54051 CVE-2026-54051: network-ai npm Package OS Command Injection
- CVE-2026-54420 LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
- CVE-2026-54769 CVE-2026-54769: Langroid TableChatAgent Sandbox Escape via eval() RCE
- CVE-2026-54782 CoreWCF SAML Token Signature Validation Authentication Bypass (CVE-2026-54782)
- CVE-2026-56155 Microsoft AD FS Insufficient Access Control Granularity Exploitation (CVE-2026-56155)
- CVE-2026-56164 Microsoft SharePoint Server Missing Authentication for Critical Function (CVE-2026-56164)
- CVE-2026-56290 CVE-2026-56290: Joomlack Page Builder Improper Access Control Exploitation
- T1034 Path Interception
- T1037 Boot or Logon Initialization Scripts
- T1037.001 Logon Script (Windows)
- T1037.002 Login Hook
- T1037.003 Network Logon Script
- T1037.004 RC Scripts
- T1037.005 Startup Items
- T1053 Scheduled Task/Job
- T1053.002 At
- T1053.003 Cron
- T1053.005 Scheduled Task
- T1053.006 Systemd Timers
- T1053.007 Container Orchestration Job
- T1055 Process Injection
- T1055.001 Dynamic-link Library Injection
- T1055.002 Portable Executable Injection
- T1055.003 Thread Execution Hijacking
- T1055.004 Asynchronous Procedure Call
- T1055.005 Thread Local Storage
- T1055.008 Ptrace System Calls
- T1055.009 Proc Memory
- T1055.011 Extra Window Memory Injection
- T1055.012 Process Hollowing
- T1055.013 Process Doppelganging
- T1055.014 VDSO Hijacking
- T1055.015 ListPlanting
- T1068 Exploitation for Privilege Escalation
- T1078 Valid Accounts
- T1078.001 Default Accounts
- T1078.002 Domain Accounts
- T1078.003 Local Accounts
- T1078.004 Cloud Accounts
- T1098 Account Manipulation
- T1098.001 Additional Cloud Credentials
- T1098.002 Additional Email Delegate Permissions
- T1098.003 Additional Cloud Roles
- T1098.004 SSH Authorized Keys
- T1098.005 Device Registration
- T1098.006 Additional Container Cluster Roles
- T1098.007 Additional Local or Domain Groups
- T1134 Access Token Manipulation
- T1134.001 Token Impersonation/Theft
- T1134.002 Create Process with Token
- T1134.003 Make and Impersonate Token
- T1134.004 Parent PID Spoofing
- T1134.005 SID-History Injection
- T1484 Domain or Tenant Policy Modification
- T1484.001 Group Policy Modification
- T1484.002 Trust Modification
- T1543 Create or Modify System Process
- T1543.001 Launch Agent
- T1543.002 Systemd Service
- T1543.003 Windows Service
- T1543.004 Launch Daemon
- T1543.005 Container Service
- T1546 Event Triggered Execution
- T1546.001 Change Default File Association
- T1546.002 Screensaver
- T1546.003 Windows Management Instrumentation Event Subscription
- T1546.004 Unix Shell Configuration Modification
- T1546.005 Trap
- T1546.006 LC_LOAD_DYLIB Addition
- T1546.007 Netsh Helper DLL
- T1546.008 Accessibility Features
- T1546.009 AppCert DLLs
- T1546.010 AppInit DLLs
- T1546.011 Application Shimming
- T1546.012 Image File Execution Options Injection
- T1546.013 PowerShell Profile
- T1546.014 Emond
- T1546.015 Component Object Model Hijacking
- T1546.016 Installer Packages
- T1546.017 Udev Rules
- T1546.018 Python Startup Hooks
- T1547 Boot or Logon Autostart Execution
- T1547.001 Registry Run Keys / Startup Folder
- T1547.002 Authentication Package
- T1547.003 Time Providers
- T1547.004 Winlogon Helper DLL
- T1547.005 Security Support Provider
- T1547.006 Kernel Modules and Extensions
- T1547.007 Re-opened Applications
- T1547.008 LSASS Driver
- T1547.009 Shortcut Modification
- T1547.010 Port Monitors
- T1547.012 Print Processors
- T1547.013 XDG Autostart Entries
- T1547.014 Active Setup
- T1547.015 Login Items
- T1548 Abuse Elevation Control Mechanism
- T1548.001 Setuid and Setgid
- T1548.002 Bypass User Account Control
- T1548.003 Sudo and Sudo Caching
- T1548.004 Elevated Execution with Prompt
- T1548.005 Temporary Elevated Cloud Access
- T1548.006 TCC Manipulation
- T1574 Hijack Execution Flow
- T1574.001 DLL
- T1574.002 DLL Side-Loading
- T1574.004 Dylib Hijacking
- T1574.005 Executable Installer File Permissions Weakness
- T1574.006 Dynamic Linker Hijacking
- T1574.007 Path Interception by PATH Environment Variable
- T1574.008 Path Interception by Search Order Hijacking
- T1574.009 Path Interception by Unquoted Path
- T1574.010 Services File Permissions Weakness
- T1574.011 Services Registry Permissions Weakness
- T1574.012 COR_PROFILER
- T1574.013 KernelCallbackTable
- T1574.014 AppDomainManager
- T1611 Escape to Host
Related tactics
266 detections
225 detections