// MITRE ATT&CK
🎯 Privilege Escalation TA0004
MITRE ATT&CK techniques under the Privilege Escalation tactic (26). Each explains the "how" the adversary pursues in this phase.
T1546.013
PowerShell Profile T1546.006
LC_LOAD_DYLIB Addition T1548.002
Bypass User Account Control T1548.003
Sudo and Sudo Caching T1546.011
Application Shimming T1611
Escape to Host T1546.005
Trap T1548
Abuse Elevation Control Mechanism T1548.001
Setuid and Setgid T1546.012
Image File Execution Options Injection T1548.005
Temporary Elevated Cloud Access T1546.008
Accessibility Features T1546.009
AppCert DLLs T1546.003
Windows Management Instrumentation Event Subscription T1546.001
Change Default File Association T1546.014
Emond T1068
Exploitation for Privilege Escalation T1546
Event Triggered Execution T1546.004
Unix Shell Configuration Modification T1548.004
Elevated Execution with Prompt T1546.015
Component Object Model Hijacking T1546.010
AppInit DLLs T1546.002
Screensaver T1546.016
Installer Packages T1548.006
TCC Manipulation T1546.007
Netsh Helper DLL
PowerShell Profile T1546.006
LC_LOAD_DYLIB Addition T1548.002
Bypass User Account Control T1548.003
Sudo and Sudo Caching T1546.011
Application Shimming T1611
Escape to Host T1546.005
Trap T1548
Abuse Elevation Control Mechanism T1548.001
Setuid and Setgid T1546.012
Image File Execution Options Injection T1548.005
Temporary Elevated Cloud Access T1546.008
Accessibility Features T1546.009
AppCert DLLs T1546.003
Windows Management Instrumentation Event Subscription T1546.001
Change Default File Association T1546.014
Emond T1068
Exploitation for Privilege Escalation T1546
Event Triggered Execution T1546.004
Unix Shell Configuration Modification T1548.004
Elevated Execution with Prompt T1546.015
Component Object Model Hijacking T1546.010
AppInit DLLs T1546.002
Screensaver T1546.016
Installer Packages T1548.006
TCC Manipulation T1546.007
Netsh Helper DLL
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.