{"id":"T1548","name":"Abuse Elevation Control Mechanism","url":"https://attack.mitre.org/techniques/T1548","tactics":["privilege-escalation"],"platforms":["Linux","macOS","Windows","IaaS","Office Suite","Identity Provider"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0345","stix_id":"x-mitre-detection-strategy--9646aa18-4ebf-43c8-bf4c-670063bc5ef8","name":"Detection Strategy for Abuse Elevation Control Mechanism (T1548)","url":"https://attack.mitre.org/detectionstrategies/DET0345","analytics":[{"id":"AN0975","stix_id":"x-mitre-analytic--11f18771-dd49-45f7-8ef5-05d3426d82d5","name":"Analytic 0975","description":"Correlate registry modifications (e.g., UAC bypass registry keys), unusual parent-child process relationships (e.g., control.exe spawning cmd.exe), and unsigned elevated process executions with non-standard tokens or elevation flags.","url":"https://attack.mitre.org/detectionstrategies/DET0345#AN0975","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4672","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ElevatedProcessPath","description":"Paths to monitor for unsigned or unexpected elevated binaries"},{"field":"ParentProcessName","description":"Parent-child execution chains that are suspicious in the local environment"},{"field":"TimeWindow","description":"Time between registry modification and elevated process spawn"}],"live":true,"detection_strategies":["DET0345"],"techniques":["T1548"]},{"id":"AN0976","stix_id":"x-mitre-analytic--90a8d89c-f54a-49dd-8734-6f85e5e3a2a5","name":"Analytic 0976","description":"Monitor audit logs for setuid/setgid bit changes, executions where UID ≠ EUID (indicative of sudo or privilege escalation), and high-integrity binaries launched by unprivileged users.","url":"https://attack.mitre.org/detectionstrategies/DET0345#AN0976","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"setuid or setgid bit changes","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve with UID ≠ EUID","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"sudo or pkexec invocation","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"WatchedDirectories","description":"Paths where unauthorized setuid binaries may be dropped"},{"field":"UserContext","description":"Which users are allowed to run sudo/pkexec or modify binaries"},{"field":"TimeWindow","description":"Duration between file permission change and elevated command execution"}],"live":true,"detection_strategies":["DET0345"],"techniques":["T1548"]},{"id":"AN0977","stix_id":"x-mitre-analytic--d8b422b3-50e7-48cc-bfa1-a6e0cecf5761","name":"Analytic 0977","description":"Detect execution of `/usr/libexec/security_authtrampoline` or use of AuthorizationExecuteWithPrivileges API, and monitor process lineage for unusual launches of GUI apps with escalated privileges.","url":"https://attack.mitre.org/detectionstrategies/DET0345#AN0977","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"authorization execute privilege requests","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"macos-unifiedlog"},{"name":"auditd:SYSCALL","channel":"execve with escalated privileges","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"auditd-syscall"},{"name":"fs:fsusage","channel":"binary execution of security_authtrampoline","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"fs-fsusage"}],"mutable_elements":[{"field":"WatchedBinaries","description":"Specify binaries frequently targeted for privilege escalation"},{"field":"ExecutionParent","description":"Which applications should never be allowed to spawn elevated processes"}],"live":true,"detection_strategies":["DET0345"],"techniques":["T1548"]},{"id":"AN0978","stix_id":"x-mitre-analytic--6385ccc0-f1a9-4198-997e-dec943e88db7","name":"Analytic 0978","description":"Monitor for unexpected privilege elevation operations via SAML assertion manipulation, role injection, or changes to identity mappings that result in access escalation.","url":"https://attack.mitre.org/detectionstrategies/DET0345#AN0978","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:signinlogs","channel":"unusual role assumption or elevation path","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"azure-signinlogs"}],"mutable_elements":[{"field":"AuthorizedRoleMappings","description":"Roles or groups that should never be assumed outside designated paths"},{"field":"TimeWindow","description":"Time between assertion issuance and critical privilege use"}],"live":true,"detection_strategies":["DET0345"],"techniques":["T1548"]},{"id":"AN0979","stix_id":"x-mitre-analytic--9465ea54-a81a-4d00-a75d-e0b7f3392bb8","name":"Analytic 0979","description":"Detect sudden privilege escalations such as IAM role changes, user-assigned privilege boundaries, or elevation via assumed roles beyond normal behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0345#AN0979","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"role privilege expansion detected","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"cross-account or unexpected assume role","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"PermittedRoleTransitions","description":"Define valid transitions between IAM roles"},{"field":"CrossAccountBoundary","description":"Should flag if assumption crosses trust boundary"}],"live":true,"detection_strategies":["DET0345"],"techniques":["T1548"]}],"live":true,"version":"1.0","techniques":["T1548"]}],"sigma_rules":[{"id":"00eee2a5-fdb0-4746-a21d-e43fbdea5681","title":"Linux Doas Conf File Creation","author":"Sittikorn S, Teoderick Contreras","status":"stable","level":"medium","date":"2022-01-20","modified":"2022-12-31","description":"Detects the creation of doas.conf file in linux host platform.","references":["https://research.splunk.com/endpoint/linux_doas_conf_file_creation/","https://www.makeuseof.com/how-to-install-and-use-doas/"],"logsource":{"product":"linux","category":"file_event"},"tags":["attack.privilege-escalation","attack.t1548"],"path":"rules/linux/file_event/file_event_lnx_doas_conf_creation.yml","techniques":["T1548"],"cves":[]},{"id":"067d8238-7127-451c-a9ec-fa78045b618b","title":"Linux Doas Tool Execution","author":"Sittikorn S, Teoderick Contreras","status":"stable","level":"low","date":"2022-01-20","modified":null,"description":"Detects the doas tool execution in linux host platform. This utility tool allow standard users to perform tasks as root, the same way sudo does.","references":["https://research.splunk.com/endpoint/linux_doas_tool_execution/","https://www.makeuseof.com/how-to-install-and-use-doas/"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1548"],"path":"rules/linux/process_creation/proc_creation_lnx_doas_execution.yml","techniques":["T1548"],"cves":[]},{"id":"07743f65-7ec9-404a-a519-913db7118a8d","title":"COM Hijack via Sdclt","author":"Omkar Gudhate","status":"test","level":"high","date":"2020-09-27","modified":"2023-09-28","description":"Detects changes to 'HKCU\\Software\\Classes\\Folder\\shell\\open\\command\\DelegateExecute'","references":["http://blog.sevagas.com/?Yet-another-sdclt-UAC-bypass","https://www.exploit-db.com/exploits/47696"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1546","attack.t1548"],"path":"rules/windows/registry/registry_set/registry_set_comhijack_sdclt.yml","techniques":["T1546","T1548"],"cves":[]},{"id":"0922467f-db53-4348-b7bf-dee8d0d348c6","title":"New CA Policy by Non-approved Actor","author":"Corissa Koopmans, '@corissalea'","status":"test","level":"medium","date":"2022-07-18","modified":null,"description":"Monitor and alert on conditional access changes.","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-infrastructure"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.privilege-escalation","attack.t1548"],"path":"rules/cloud/azure/audit_logs/azure_aad_secops_new_ca_policy_addedby_bad_actor.yml","techniques":["T1548"],"cves":[]},{"id":"174afcfa-6e40-4ae9-af64-496546389294","title":"Credential Dumping Attempt Via Svchost","author":"Florent Labouyrie","status":"test","level":"high","date":"2021-04-30","modified":"2022-10-09","description":"Detects when a process tries to access the memory of svchost to potentially dump credentials.","references":["Internal Research"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.privilege-escalation","attack.t1548"],"path":"rules/windows/process_access/proc_access_win_svchost_credential_dumping.yml","techniques":["T1548"],"cves":[]},{"id":"26e7c5e2-6545-481e-b7e6-050143459635","title":"CA Policy Removed by Non Approved Actor","author":"Corissa Koopmans, '@corissalea'","status":"test","level":"medium","date":"2022-07-19","modified":null,"description":"Monitor and alert on conditional access changes where non approved actor removed CA Policy.","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-infrastructure#conditional-access"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.privilege-escalation","attack.credential-access","attack.persistence","attack.defense-impairment","attack.t1548","attack.t1556"],"path":"rules/cloud/azure/audit_logs/azure_aad_secops_ca_policy_removedby_bad_actor.yml","techniques":["T1548","T1556"],"cves":[]},{"id":"33b3cfb1-574e-44b9-b527-fbf9303b9d7b","title":"Potential Exploitation of CVE-2025-5054 or CVE-2025-4598","author":"Milad Cheraghi","status":"experimental","level":"medium","date":"2026-04-28","modified":null,"description":"Detects attempts of an attacker to enable core dumps for set-user-ID (SUID) processes by modifying the system file /proc/sys/fs/suid_dumpable, typically by setting its value to 1 or 2.\nEnabling this feature allows memory dumps (core dumps) of SUID processes, which usually run with elevated privileges.\nThese dumps may contain sensitive information such as passwords, cryptographic keys or other secrets.\nCVE-2025-5054: Information leak via core dumps from SUID binaries using apport.\nCVE-2025-4598: Information disclosure in systemd-coredump due to insecure handling of SUID process memory dumps.\n","references":["https://nvd.nist.gov/vuln/detail/CVE-2025-5054","https://nvd.nist.gov/vuln/detail/CVE-2025-4598","https://blog.qualys.com/vulnerabilities-threat-research/2025/05/29/qualys-tru-discovers-two-local-information-disclosure-vulnerabilities-in-apport-and-systemd-coredump-cve-2025-5054-and-cve-2025-4598"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.privilege-escalation","attack.credential-access","attack.t1548","attack.t1003","cve.2025-5054","cve.2025-4598","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE_2025_4598/proc_creation_lnx_exploit_cve_2025_5054_or_cve_2025_4598.yml","techniques":["T1548","T1003"],"cves":["CVE-2025-5054","CVE-2025-4598"]},{"id":"3a716279-c18c-4488-83be-f9ececbfb9fc","title":"Linux Setgid Capability Set on a Binary via Setcap Utility","author":"Luc Génaux","status":"experimental","level":"low","date":"2026-01-24","modified":null,"description":"Detects the use of the 'setcap' utility to set the 'setgid' capability (cap_setgid) on a binary file.\nThis capability allows a non privileged process to make arbitrary manipulations of group IDs (GIDs), including setting its current GID to a value that would otherwise be restricted (i.e. GID 0, the root group).\nThis behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.\n","references":["https://man7.org/linux/man-pages/man8/setcap.8.html","https://dfir.ch/posts/linux_capabilities/","https://juggernaut-sec.com/capabilities/#cap_setgid"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1548","attack.t1554"],"path":"rules/linux/process_creation/proc_creation_lnx_cap_setgid.yml","techniques":["T1548","T1554"],"cves":[]},{"id":"50a3c7aa-ec29-44a4-92c1-fce229eef6fc","title":"CA Policy Updated by Non Approved Actor","author":"Corissa Koopmans, '@corissalea'","status":"test","level":"medium","date":"2022-07-19","modified":"2024-05-28","description":"Monitor and alert on conditional access changes. Is Initiated by (actor) approved to make changes? Review Modified Properties and compare \"old\" vs \"new\" value.","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-infrastructure#conditional-access"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.privilege-escalation","attack.credential-access","attack.persistence","attack.defense-impairment","attack.t1548","attack.t1556"],"path":"rules/cloud/azure/audit_logs/azure_aad_secops_ca_policy_updatedby_bad_actor.yml","techniques":["T1548","T1556"],"cves":[]},{"id":"665e2d43-70dc-4ccc-9d27-026c9dd7ed9c","title":"User Removed From Group With CA Policy Modification Access","author":"Mark Morowczynski '@markmorow', Thomas Detzner '@tdetzner'","status":"test","level":"medium","date":"2022-08-04","modified":null,"description":"Monitor and alert on group membership removal of groups that have CA policy modification access","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-infrastructure#conditional-access"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.privilege-escalation","attack.credential-access","attack.persistence","attack.defense-impairment","attack.t1548","attack.t1556"],"path":"rules/cloud/azure/audit_logs/azure_group_user_removal_ca_modification.yml","techniques":["T1548","T1556"],"cves":[]},{"id":"749c9f5e-b353-4b90-a9c1-05243357ca4b","title":"Potential Privilege Escalation via Local Kerberos Relay over LDAP","author":"Elastic, @SBousseaden","status":"test","level":"high","date":"2022-04-27","modified":"2024-08-13","description":"Detects a suspicious local successful logon event where the Logon Package is Kerberos, the remote address is set to localhost, and the target user SID is the built-in local Administrator account.\nThis may indicate an attempt to leverage a Kerberos relay attack variant that can be used to elevate privilege locally from a domain joined limited user to local System privileges.\n","references":["https://twitter.com/sbousseaden/status/1518976397364056071?s=12&t=qKO5eKHvWhAP19a50FTZ7g","https://github.com/elastic/detection-rules/blob/5fe7833312031a4787e07893e27e4ea7a7665745/rules/_deprecated/privilege_escalation_krbrelayup_suspicious_logon.toml#L38"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.credential-access","attack.t1548"],"path":"rules/windows/builtin/security/account_management/win_security_susp_privesc_kerberos_relay_over_ldap.yml","techniques":["T1548"],"cves":[]},{"id":"76737c19-66ee-4c07-b65a-a03301d1573d","title":"GCP Break-glass Container Workload Deployed","author":"Bryan Lim","status":"test","level":"medium","date":"2024-01-12","modified":null,"description":"Detects the deployment of workloads that are deployed by using the break-glass flag to override Binary Authorization controls.\n","references":["https://cloud.google.com/binary-authorization"],"logsource":{"product":"gcp","service":"gcp.audit"},"tags":["attack.privilege-escalation","attack.t1548"],"path":"rules/cloud/gcp/audit/gcp_breakglass_container_workload_deployed.yml","techniques":["T1548"],"cves":[]},{"id":"883835a7-df45-43e4-bf1d-4268768afda4","title":"Regedit as Trusted Installer","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-05-27","modified":"2022-10-09","description":"Detects a regedit started with TrustedInstaller privileges or by ProcessHacker.exe","references":["https://twitter.com/1kwpeter/status/1397816101455765504"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1548"],"path":"rules/windows/process_creation/proc_creation_win_regedit_trustedinstaller.yml","techniques":["T1548"],"cves":[]},{"id":"905d389b-b853-46d0-9d3d-dea0d3a3cd49","title":"AWS STS AssumeRole Misuse","author":"Austin Songer @austinsonger","status":"test","level":"low","date":"2021-07-24","modified":"2022-10-09","description":"Identifies the suspicious use of AssumeRole. Attackers could move laterally and escalate privileges.","references":["https://github.com/elastic/detection-rules/pull/1214","https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRole.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.lateral-movement","attack.privilege-escalation","attack.t1548","attack.t1550","attack.t1550.001"],"path":"rules/cloud/aws/cloudtrail/aws_sts_assumerole_misuse.yml","techniques":["T1548","T1550","T1550.001"],"cves":[]},{"id":"91c95675-1f27-46d0-bead-d1ae96b97cd3","title":"User Added To Group With CA Policy Modification Access","author":"Mark Morowczynski '@markmorow', Thomas Detzner '@tdetzner'","status":"test","level":"medium","date":"2022-08-04","modified":null,"description":"Monitor and alert on group membership additions of groups that have CA policy modification access","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-infrastructure#conditional-access"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.privilege-escalation","attack.credential-access","attack.persistence","attack.defense-impairment","attack.t1548","attack.t1556"],"path":"rules/cloud/azure/audit_logs/azure_group_user_addition_ca_modification.yml","techniques":["T1548","T1556"],"cves":[]},{"id":"a0cb7110-edf0-47a4-9177-541a4083128a","title":"Vulnerable Netlogon Secure Channel Connection Allowed","author":"NVISO","status":"test","level":"high","date":"2020-09-15","modified":"2022-12-25","description":"Detects that a vulnerable Netlogon secure channel connection was allowed, which could be an indicator of CVE-2020-1472.","references":["https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc"],"logsource":{"product":"windows","service":"system"},"tags":["attack.privilege-escalation","attack.t1548"],"path":"rules/windows/builtin/system/netlogon/win_system_vul_cve_2020_1472.yml","techniques":["T1548"],"cves":[]},{"id":"a7f3c891-2e4d-4b6a-9f8c-d5e2a1b04c73","title":"Registry Hive File Staged Outside Standard User Profile Path","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-07-23","modified":null,"description":"Detects the creation of a registry hive file (UsrClass.dat or NTUSER.DAT) outside of the standard user profile path.\nThese files generally contain various user-specific registry settings and are typically located in the user's profile directory.\nStaging these files outside of the standard path can be indicative of an attacker attempting to manipulate user registry settings\nfor persistence, privilege escalation, or dump user registry hives for credential harvesting.\n","references":["https://github.com/MSNightmare/LegacyHive","https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.t1548","attack.credential-access","attack.t1003"],"path":"rules/windows/file/file_event/file_event_win_susp_registry_hive_file_creation.yml","techniques":["T1548","T1003"],"cves":[]},{"id":"b45ab1d2-712f-4f01-a751-df3826969807","title":"AWS STS GetSessionToken Misuse","author":"Austin Songer @austinsonger","status":"test","level":"low","date":"2021-07-24","modified":"2022-10-09","description":"Identifies the suspicious use of GetSessionToken. Tokens could be created and used by attackers to move laterally and escalate privileges.","references":["https://github.com/elastic/detection-rules/pull/1213","https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.lateral-movement","attack.privilege-escalation","attack.t1548","attack.t1550","attack.t1550.001"],"path":"rules/cloud/aws/cloudtrail/aws_sts_getsessiontoken_misuse.yml","techniques":["T1548","T1550","T1550.001"],"cves":[]},{"id":"d522eca2-2973-4391-a3e0-ef0374321dae","title":"Abused Debug Privilege by Arbitrary Parent Processes","author":"Semanur Guneysu @semanurtg, oscd.community","status":"test","level":"high","date":"2020-10-28","modified":"2022-11-11","description":"Detection of unusual child processes by different system processes","references":["https://image.slidesharecdn.com/kheirkhabarovoffzonefinal-181117201458/95/hunting-for-privilege-escalation-in-windows-environment-74-638.jpg"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1548"],"path":"rules/windows/process_creation/proc_creation_win_susp_abusing_debug_privilege.yml","techniques":["T1548"],"cves":[]},{"id":"dae8171c-5ec6-4396-b210-8466585b53e9","title":"SCM Database Privileged Operation","author":"Roberto Rodriguez @Cyb3rWard0g, Tim Shelton","status":"test","level":"medium","date":"2019-08-15","modified":"2022-09-18","description":"Detects non-system users performing privileged operation os the SCM database","references":["https://threathunterplaybook.com/hunts/windows/190826-RemoteSCMHandle/notebook.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.t1548"],"path":"rules/windows/builtin/security/win_security_scm_database_privileged_operation.yml","techniques":["T1548"],"cves":[]},{"id":"e52cb31c-10ed-4aea-bcb7-593c9f4a315b","title":"UAC Bypass via Windows Firewall Snap-In Hijack","author":"Tim Rauch, Elastic (idea)","status":"test","level":"medium","date":"2022-09-27","modified":null,"description":"Detects attempts to bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in","references":["https://www.elastic.co/guide/en/security/current/uac-bypass-via-windows-firewall-snap-in-hijack.html#uac-bypass-via-windows-firewall-snap-in-hijack"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1548"],"path":"rules/windows/process_creation/proc_creation_win_uac_bypass_hijacking_firwall_snap_in.yml","techniques":["T1548"],"cves":[]},{"id":"ed447910-bc30-4575-a598-3a2e49516a7a","title":"Linux Setuid Capability Set on a Binary via Setcap Utility","author":"Luc Génaux","status":"experimental","level":"low","date":"2026-01-24","modified":null,"description":"Detects the use of the 'setcap' utility to set the 'setuid' capability (cap_setuid) on a binary file.\nThis capability allows a non privileged process to make arbitrary manipulations of user IDs (UIDs), including setting its current UID to a value that would otherwise be restricted (i.e. UID 0, the root user).\nThis behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.\n","references":["https://man7.org/linux/man-pages/man8/setcap.8.html","https://dfir.ch/posts/linux_capabilities/","https://juggernaut-sec.com/capabilities/#cap_setuid"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1548","attack.t1554"],"path":"rules/linux/process_creation/proc_creation_lnx_cap_setuid.yml","techniques":["T1548","T1554"],"cves":[]},{"id":"f43f5d2f-3f2a-4cc8-b1af-81fde7dbaf0e","title":"AWS Suspicious SAML Activity","author":"Austin Songer","status":"test","level":"medium","date":"2021-09-22","modified":"2022-12-18","description":"Identifies when suspicious SAML activity has occurred in AWS. An adversary could gain backdoor access via SAML.","references":["https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateSAMLProvider.html","https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRoleWithSAML.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.initial-access","attack.lateral-movement","attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1078","attack.t1548","attack.t1550","attack.t1550.001"],"path":"rules/cloud/aws/cloudtrail/aws_susp_saml_activity.yml","techniques":["T1078","T1548","T1550","T1550.001"],"cves":[]},{"id":"fe10751f-1995-40a5-aaa2-c97ccb4123fe","title":"Linux Capabilities Discovery","author":"Pawel Mazur","status":"test","level":"low","date":"2021-11-28","modified":"2022-12-25","description":"Detects attempts to discover the files with setuid/setgid capability on them. That would allow adversary to escalate their privileges.","references":["https://man7.org/linux/man-pages/man8/getcap.8.html","https://www.hackingarticles.in/linux-privilege-escalation-using-capabilities/","https://mn3m.info/posts/suid-vs-capabilities/","https://int0x33.medium.com/day-44-linux-capabilities-privilege-escalation-via-openssl-with-selinux-enabled-and-enforced-74d2bec02099"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.discovery","attack.privilege-escalation","attack.t1083","attack.t1548"],"path":"rules/linux/auditd/execve/lnx_auditd_capabilities_discovery.yml","techniques":["T1083","T1548"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-44221","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-2783","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-1388","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-23131","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}