T1548Techniqueprivilege-escalationdefense-evasionagent-callable

T1548Abuse Elevation Control Mechanism

Platforms: Linux · macOS · Windows · IaaS · Office Suite · Identity Provider

ATT&CK version: v19.1

What it is

Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk.(Citation: TechNet How UAC Works)(Citation: sudo man page 2018) An adversary can perform several methods to take advantage of built-in control mechanisms in order to escalate privileges on a system.(Citation: OSX Keydnap malware)(Citation: Fortinet Fareit)

ATT&CK tactics· 2

Privilege EscalationDefense Evasion

References

  1. https://attack.mitre.org/techniques/T1548
  2. https://technet.microsoft.com/en-us/itpro/windows/keep-secure/how-user-account-control-works
  3. https://www.welivesecurity.com/2016/07/06/new-osxkeydnap-malware-hungry-credentials/
  4. https://blog.fortinet.com/2016/12/16/malicious-macro-bypasses-uac-to-elevate-privilege-for-fareit-malware
  5. https://www.sudo.ws/
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.
T1548: Abuse Elevation Control Mechanism | SQUR Knowledge Base