Abuse Elevation Control Mechanism

T1548

Technique with 6 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk. An adversary can perform several methods to take advantage of built-in control mechanisms in order to escalate privileges on a system.

Detection rules153

Rules on DetectionCode tagged with T1548 or one of its sub-techniques.

Sigma84

RuleLevelLog sourceTechnique
HackTool - Empire PowerShell UAC Bypasscriticalwindows / process_creationT1548.002
Sudo Privilege Escalation CVE-2019-14287 - Builtincriticallinux / NULLT1548.003
TrustedPath UAC Bypass Patterncriticalwindows / process_creationT1548.002
Abused Debug Privilege by Arbitrary Parent Processeshighwindows / process_creationT1548
Bypass UAC Using DelegateExecutehighwindows / registry_setT1548.002
Bypass UAC Using SilentCleanup Taskhighwindows / registry_setT1548.002
Bypass UAC via CMSTPhighwindows / process_creationT1548.002
Bypass UAC via Fodhelper.exehighwindows / process_creationT1548.002
Bypass UAC via WSReset.exehighwindows / process_creationT1548.002
CMSTP UAC Bypass via COM Object Accesshighwindows / process_creationT1548.002
COM Hijack via Sdclthighwindows / registry_setT1548
Credential Dumping Attempt Via Svchosthighwindows / process_accessT1548
Explorer NOUACCHECK Flaghighwindows / process_creationT1548.002
HackTool - UACMe Akagi Executionhighwindows / process_creationT1548.002
HackTool - WinPwn Executionhighwindows / process_creationT1548.002

Splunk69

RuleTypeRiskData sourceTechnique
Allow Operation with Consent AdminTTPNULLSysmon EventID 13T1548
Disable UAC Remote RestrictionTTPNULLSysmon EventID 13T1548.002
Disabling Remote User Account ControlTTPNULLSysmon EventID 13T1548.002
Eventvwr UAC BypassTTPNULLSysmon EventID 13T1548.002
FodHelper UAC BypassTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1548.002
Linux APT Privilege EscalationAnomalyNULLSysmon for Linux EventID 1, Cisco Isovalent Process ExecT1548.003
Linux apt-get Privilege EscalationAnomalyNULLSysmon for Linux EventID 1, Cisco Isovalent Process ExecT1548.003
Linux Auditd Doas Conf File CreationTTPNULLLinux Auditd Path, Linux Auditd CwdT1548.003
Linux Auditd Doas Tool ExecutionAnomalyNULLLinux Auditd SyscallT1548.003
Linux Auditd Nopasswd Entry In Sudoers FileAnomalyNULLLinux Auditd ProctitleT1548.003
Linux Auditd Possible Access To Sudoers FileAnomalyNULLLinux Auditd Path, Linux Auditd CwdT1548.003
Linux Auditd Setuid Using Chmod UtilityAnomalyNULLLinux Auditd ProctitleT1548.001
Linux Auditd Setuid Using Setcap UtilityTTPNULLLinux Auditd ExecveT1548.001
Linux Auditd Sudo Or Su ExecutionAnomalyNULLLinux Auditd ProctitleT1548.003
Linux AWK Privilege EscalationAnomalyNULLSysmon for Linux EventID 1T1548.003

Sub-techniques6

IDNameExamples
T1548.001Setuid and Setgid2
T1548.002Bypass User Account Control63
T1548.003Sudo and Sudo Caching6
T1548.004Elevated Execution with Prompt1
T1548.005Temporary Elevated Cloud Access0
T1548.006TCC Manipulation1

Groups1

Software1

Campaigns0

None recorded.

Procedure examples2

Groups1

Used byProcedure example
GroupUNC3886

UNC3886 has used vSphere Installation Bundles (VIBs) that contained modified descriptor XML files with the `acceptance-level` set to `partner` which allowed for privilege escalation.

Software1

Used byProcedure example
MalwareRaspberry Robin

Raspberry Robin implements a variation of the ucmDccwCOMMethod technique abusing the Windows AutoElevate backdoor to bypass UAC while elevating privileges.

References4

  1. Fortinet Fareit Open source
    Salvio, J., Joven, R. (2016, December 16). Malicious Macro Bypasses UAC to Elevate Privilege for Fareit Malware. Retrieved December 27, 2016.
  2. OSX Keydnap malware Open source
    Marc-Etienne M.Leveille. (2016, July 6). New OSX/Keydnap malware is hungry for credentials. Retrieved July 3, 2017.
  3. TechNet How UAC Works Open source
    Lich, B. (2016, May 31). How User Account Control Works. Retrieved June 3, 2016.
  4. sudo man page 2018 Open source
    Todd C. Miller. (2018). Sudo Man Page. Retrieved March 19, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.