FORENSIA

ATT&CK · T1068

Exploitation for Privilege Escalation

Tactics: privilege-escalation

About

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions. When initially gaining access to a system, an adversary may be operating within a lower privileged process which will prevent them from accessing certain resources on the system. Vulnerabilities may exist, usually in operating system components and software commonly running at higher permissions, that can be exploited to gain higher levels of access on the system. This could enable someone to move from unprivileged or user level permissions to SYSTEM or root permissions depending on the component that is vulnerable. This could also enable an adversary to move from a virtualized environment, such as within a virtual machine or container, onto the underlying host. This may be a necessary step for an adversary compromising an endpoint system that has been properly configured and limits other privilege escalation methods. Adversaries may bring a signed vulnerable driver onto a compromised machine so that they can exploit the vulnerability to execute code in kernel mode. This process is sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Adversaries may include the vulnerable driver with files delivered during Initial Access or download it to a compromised system via Ingress Tool Transfer or Lateral Tool Transfer.

Platforms: Containers, Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

22 known groups

Software

19 malware/tools implement this

JHUHUGITCosmicDukeRemsecCobalt StrikeWingbirdInvisiMoleEmpirePoshC2CarberpHildegardStuxnetSiloscapeProLockXCSSETPandoraZoxZeroCleareBlackByte 2.0 RansomwareEmbargo

Corpus indicators tagged with this technique

105 indicators in the corpus carry T1068.

IndicatorTypeFamilySevSrc
cve-2026-22584cve852
cve-2026-4368cveransomware851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2025-23304cve852
5bb5cffda4647940919a185df37aab2aef71ca3010a6c1d05bdcc8bc8fb3af3fsha256801
49c827cf48efb122a9d6fd87b426482b7496ccd4a2dbca31ebbf6b2b80c98530sha256801
42692bd13333623e9085d0c1326574a3391efcbf18158bb04972103c9ee4a3b8hash803
b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7bsha256802
2654c08491a0f7c4a3dfc6282de5638bhash803
625b6535321d58bb5c613e85332bf731hash803
b8eed63ab9cbdca494f26a6f66bfd4a0a693b3f0hash803
873f1277a42de5c82f869459e7fb7c94554a642bhash803
fbf0b6abd651622864eb921f891b3e7c538fc8a9hash801
123e80a34508c4dede7cc70e76931fcchash803
9ca9432b0d29204cb5420a1a6b01533d4552130c2a8a5ecd7837efadefb4a046sha256ransomware801
7ee17efef04bb7c9de90d5210263ed6993f867e5a11f86e65e3bb1362c7de237sha256ransomware801
f4d77958a12a0778283d3e679b24b18f82e332c4hash803
681075027553546c119ec447eb8df84633dcffcehash803
c277ae5a4dd62f51de5278790796cd2700de7f77ea17762e97729f27872d076bsha256ransomware801
00e195d94d3b1f7092eb9ed132f89d1bhash803
838ea8d6b201e2eed181f3fd890f99ecb6178b52hash801
84ad78b2bab946c3677fdc28ebd8a774hash803
b1b7aaa5bd4408a4d3003a9fabcdd041hash803
b439749a581ac5a29b5c9d91fc092bf4ceaa76a4hash803
e0ab84da2d2783c8cae3624e8ce58b99ad79219753b249671ff7f743abdacc35hash801
e952c18272efa1c3d73d0a5381bcf443c02743fehash803
f8d93c1769e877aae7e7d5c289a467b5ae371c7ahash803
9c44bc9373377831c45dd0ac2661a28ehash803
458653300b48c90a8659b9e9cadc13717bce42b6hash803

Showing the top 30 by severity of 105.