T1548 Abuse Elevation Control Mechanism — Detection & Response
Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user may perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk.
Coverage at a glance
- Detections shipped
- 4
- Avg. verdict time
- < 5 min
- Data sources
- 4+
Threat context
How adversaries use T1548 Abuse Elevation Control Mechanism — Detection & Response
Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user may perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk.
UAC bypass (T1548.002) is common in post-exploitation Windows payloads to elevate from a standard user process to a high-integrity process without a visible prompt. Sudo abuse (T1548.003) is the Linux equivalent, where misconfigured sudoers entries allow non-privileged users to execute commands as root. In cloud environments, T1548.005 (Temporary Elevated Cloud Access) covers the abuse of AWS STS AssumeRole, GCP impersonation, or Azure PIM to obtain short-lived elevated credentials.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| UAC Bypass via CMSTPLUA — COM object method commonly used to bypass UAC Process elevation via known UAC bypass COM object without user consent prompt. | High | CrowdStrike / SentinelOne |
| Sudo with NOPASSWD in Sudoers — Command execution via NOPASSWD sudo entry User executes root command via sudo without password, indicating a misconfigured sudoers rule being used. | Medium | Linux Audit Log |
| AWS AssumeRole to High-Privilege Role — STS AssumeRole call targeting admin-level role User or service assumes a role with AdministratorAccess or PowerUserAccess, particularly from an unusual source. | High | AWS CloudTrail |
| Azure PIM Activation Outside Business Hours — Privileged role activated at unusual time Privileged Identity Management role activated outside the user's normal working hours pattern. | Medium | Entra ID PIM Logs |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1539 Steal Web Session Cookie — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response: frequently asked questions
How does ManySignal detect UAC bypass without endpoint telemetry?
UAC bypass detection requires EDR telemetry (CrowdStrike or SentinelOne). Without an EDR, ManySignal can detect post-elevation actions (privileged API calls, new service creation) but cannot detect the bypass mechanism itself.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.