T1548: Abuse Elevation Control Mechanism

View on MITRE ATT&CK T1548
Tactic(s) Privilege Escalation, Defense Evasion
Associated CAPEC Patterns Authentication Abuse (CAPEC-114) , Privilege Escalation (CAPEC-233) , Authentication Bypass (CAPEC-115) , Privilege Abuse (CAPEC-122)

Data from MITRE ATT&CK®:

Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk. An adversary can perform several methods to take advantage of built-in control mechanisms in order to escalate privileges on a system.

© 2024 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Cyber Threat Graph Context

Explore how this ATT&CK Technique relates to the wider threat graph

Mitigations for this technique

MITRE ATT&CK Mitigations

How to detect this technique

MITRE ATT&CK Data Components

Sigma Detections for this Technique

SP800-53 Controls

See which controls can help protect against this MITRE ATT&CK technique. This is based on mappings to associated SP800-53 controls produced by the MITRE Engenuity Center for Threat-Informed Defense.