T1068 Exploitation for Privilege Escalation — Detection & Response
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code, typically to move from a lower-privileged context (user, service account, container) to a higher-privileged one (root, SYSTEM, host).
Coverage at a glance
- Detections shipped
- 5
- Avg. verdict time
- < 5 min
- Data sources
- 5+
Threat context
How adversaries use T1068 Exploitation for Privilege Escalation — Detection & Response
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code, typically to move from a lower-privileged context (user, service account, container) to a higher-privileged one (root, SYSTEM, host).
Local privilege escalation is a required step in most post-compromise operations: initial access frequently lands the attacker as an unprivileged user, and they need SYSTEM or root to disable EDR, dump LSASS, install kernel rootkits, or pivot to other identities. Common exploitation paths include kernel vulnerabilities (Dirty Pipe CVE-2022-0847, Dirty COW, nf_tables use-after-free), userland-to-root escalations (PwnKit CVE-2021-4034 in polkit's pkexec, Sudo Baron Samedit), Windows service and print-spooler bugs (PrintNightmare CVE-2021-34527, HiveNightmare), and abuse of misconfigured setuid binaries or Linux capabilities such as CAP_SYS_ADMIN, CAP_DAC_READ_SEARCH, and CAP_SYS_PTRACE. Container-focused actors chain these with escape primitives (CVE-2022-0492 cgroup escape, runc CVE-2024-21626) to break out of workloads onto the host.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| Known Kernel Exploit Signature (Dirty Pipe / PwnKit / PrintNightmare) Process behavior matching known PoC patterns: pkexec spawned with empty argv (PwnKit), splice() into read-only file (Dirty Pipe), or spoolsv.exe loading an unsigned DLL from a user-writable path (PrintNightmare). | Critical | EDR / Sysmon |
| Setuid Binary Execution From Anomalous Parent A setuid binary is invoked from an unexpected parent process (shell script dropped in /tmp, web server worker, container init) — anomalous relative to a baseline of legitimate setuid invocations. | High | Linux audit / EDR |
| Credential Process Memory Access (LSASS / lsass_dump) Process opens a handle to lsass.exe with PROCESS_VM_READ or invokes MiniDumpWriteDump against it, typically executed only after successful privilege escalation to SYSTEM. | Critical | EDR / Sysmon (Event ID 10) |
| Unexpected Token Elevation on Process Creation A child process is created with a higher integrity level or additional privileges (SeDebugPrivilege, SeImpersonatePrivilege) than the parent, indicating token manipulation or exploitation of an elevation-of-privilege flaw. | High | Windows Security 4688 / 4672 |
| Linux Capability Abuse — CAP_SYS_ADMIN or CAP_DAC_READ_SEARCH in Unexpected Context A process acquires or uses CAP_SYS_ADMIN, CAP_DAC_READ_SEARCH, or CAP_SYS_MODULE outside of expected system daemons — commonly abused for container escape and arbitrary file read as root. | High | Linux kernel telemetry (eBPF capset) |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1539 Steal Web Session Cookie — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response: frequently asked questions
How is T1068 different from T1548 (Abuse Elevation Control Mechanism)?
T1068 covers exploitation of an actual software vulnerability — a memory-corruption bug, logic flaw, or race condition — to gain elevated privileges. T1548 covers abuse of legitimate elevation mechanisms (sudo, UAC, setuid, elevated COM objects) without requiring a vulnerability. PwnKit is T1068; sudo password bypass via a misconfigured sudoers file is T1548.
Can ManySignal detect zero-day privilege escalation?
ManySignal focuses on the behavioral consequences of successful escalation rather than the exploit itself: unexpected integrity-level jumps, LSASS access from a newly-elevated process, capability acquisition in anomalous contexts, and kernel module loads outside of change windows. This behavioral layer catches novel exploits whose payloads still need to perform the same post-escalation actions.
How does container escape relate to T1068?
Container escapes typically chain a T1068 exploit (kernel bug, runc flaw, cgroups misconfiguration) with the container's own capabilities to break onto the host. ManySignal monitors container runtime telemetry for capability abuse, unexpected syscalls, and host-namespace access originating from container-scoped processes.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.