// MITRE ATT&CK

T1548 · Abuse Elevation Control Mechanism

🎯 Privilege Escalation LinuxmacOSWindowsIaaSOffice SuiteIdentity Provider

Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific user...

¿Cómo detectarlo y mitigarlo?

La detección de Abuse Elevation Control Mechanism parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.

Sub-técnicas (6)

Técnicas relacionadas

Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.