ManySignal
T1068 MITRE ATT&CK

T1068 Exploitation for Privilege Escalation — Detection & Response

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code, typically to move from a lower-privileged context (user, service account, container) to a higher-privileged one (root, SYSTEM, host).

Coverage at a glance

Detections shipped
5
Avg. verdict time
< 5 min
Data sources
5+

Threat context

How adversaries use T1068 Exploitation for Privilege Escalation — Detection & Response

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code, typically to move from a lower-privileged context (user, service account, container) to a higher-privileged one (root, SYSTEM, host).

Local privilege escalation is a required step in most post-compromise operations: initial access frequently lands the attacker as an unprivileged user, and they need SYSTEM or root to disable EDR, dump LSASS, install kernel rootkits, or pivot to other identities. Common exploitation paths include kernel vulnerabilities (Dirty Pipe CVE-2022-0847, Dirty COW, nf_tables use-after-free), userland-to-root escalations (PwnKit CVE-2021-4034 in polkit's pkexec, Sudo Baron Samedit), Windows service and print-spooler bugs (PrintNightmare CVE-2021-34527, HiveNightmare), and abuse of misconfigured setuid binaries or Linux capabilities such as CAP_SYS_ADMIN, CAP_DAC_READ_SEARCH, and CAP_SYS_PTRACE. Container-focused actors chain these with escape primitives (CVE-2022-0492 cgroup escape, runc CVE-2024-21626) to break out of workloads onto the host.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

Known Kernel Exploit Signature (Dirty Pipe / PwnKit / PrintNightmare)

Process behavior matching known PoC patterns: pkexec spawned with empty argv (PwnKit), splice() into read-only file (Dirty Pipe), or spoolsv.exe loading an unsigned DLL from a user-writable path (PrintNightmare).

Critical EDR / Sysmon

Setuid Binary Execution From Anomalous Parent

A setuid binary is invoked from an unexpected parent process (shell script dropped in /tmp, web server worker, container init) — anomalous relative to a baseline of legitimate setuid invocations.

High Linux audit / EDR

Credential Process Memory Access (LSASS / lsass_dump)

Process opens a handle to lsass.exe with PROCESS_VM_READ or invokes MiniDumpWriteDump against it, typically executed only after successful privilege escalation to SYSTEM.

Critical EDR / Sysmon (Event ID 10)

Unexpected Token Elevation on Process Creation

A child process is created with a higher integrity level or additional privileges (SeDebugPrivilege, SeImpersonatePrivilege) than the parent, indicating token manipulation or exploitation of an elevation-of-privilege flaw.

High Windows Security 4688 / 4672

Linux Capability Abuse — CAP_SYS_ADMIN or CAP_DAC_READ_SEARCH in Unexpected Context

A process acquires or uses CAP_SYS_ADMIN, CAP_DAC_READ_SEARCH, or CAP_SYS_MODULE outside of expected system daemons — commonly abused for container escape and arbitrary file read as root.

High Linux kernel telemetry (eBPF capset)

T1068 Exploitation for Privilege Escalation — Detection & Response: frequently asked questions

How is T1068 different from T1548 (Abuse Elevation Control Mechanism)?

T1068 covers exploitation of an actual software vulnerability — a memory-corruption bug, logic flaw, or race condition — to gain elevated privileges. T1548 covers abuse of legitimate elevation mechanisms (sudo, UAC, setuid, elevated COM objects) without requiring a vulnerability. PwnKit is T1068; sudo password bypass via a misconfigured sudoers file is T1548.

Can ManySignal detect zero-day privilege escalation?

ManySignal focuses on the behavioral consequences of successful escalation rather than the exploit itself: unexpected integrity-level jumps, LSASS access from a newly-elevated process, capability acquisition in anomalous contexts, and kernel module loads outside of change windows. This behavioral layer catches novel exploits whose payloads still need to perform the same post-escalation actions.

How does container escape relate to T1068?

Container escapes typically chain a T1068 exploit (kernel bug, runc flaw, cgroups misconfiguration) with the container's own capabilities to break onto the host. ManySignal monitors container runtime telemetry for capability abuse, unexpected syscalls, and host-namespace access originating from container-scoped processes.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.