M ManySignal
T1548 MITRE ATT&CK

T1548 Abuse Elevation Control Mechanism — Detection & Response

Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user may perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk.

Coverage at a glance

Detections shipped
4
Avg. verdict time
< 5 min
Data sources
4+

Threat context

How adversaries use T1548 Abuse Elevation Control Mechanism — Detection & Response

Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user may perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk.

UAC bypass (T1548.002) is common in post-exploitation Windows payloads to elevate from a standard user process to a high-integrity process without a visible prompt. Sudo abuse (T1548.003) is the Linux equivalent, where misconfigured sudoers entries allow non-privileged users to execute commands as root. In cloud environments, T1548.005 (Temporary Elevated Cloud Access) covers the abuse of AWS STS AssumeRole, GCP impersonation, or Azure PIM to obtain short-lived elevated credentials.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

UAC Bypass via CMSTPLUA — COM object method commonly used to bypass UAC

Process elevation via known UAC bypass COM object without user consent prompt.

High CrowdStrike / SentinelOne

Sudo with NOPASSWD in Sudoers — Command execution via NOPASSWD sudo entry

User executes root command via sudo without password, indicating a misconfigured sudoers rule being used.

Medium Linux Audit Log

AWS AssumeRole to High-Privilege Role — STS AssumeRole call targeting admin-level role

User or service assumes a role with AdministratorAccess or PowerUserAccess, particularly from an unusual source.

High AWS CloudTrail

Azure PIM Activation Outside Business Hours — Privileged role activated at unusual time

Privileged Identity Management role activated outside the user's normal working hours pattern.

Medium Entra ID PIM Logs

T1548 Abuse Elevation Control Mechanism — Detection & Response: frequently asked questions

How does ManySignal detect UAC bypass without endpoint telemetry?

UAC bypass detection requires EDR telemetry (CrowdStrike or SentinelOne). Without an EDR, ManySignal can detect post-elevation actions (privileged API calls, new service creation) but cannot detect the bypass mechanism itself.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.