1200KM / detection
T1068 Exploitation for Privilege Escalation — Detection Rules
Detection workspace for T1068 Exploitation for Privilege Escalation: 15 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Possible Coin Miner CPU Priority Param · test · critical · {"product":"linux","service":"auditd"}
- Buffer Overflow Attempts · test · high · {"product":"linux"}
- Linux Sudo Chroot Execution · experimental · low · {"category":"process_creation","product":"linux"}
- OMIGOD SCX RunAsProvider ExecuteScript · test · high · {"product":"linux","category":"process_creation"}
- OMIGOD SCX RunAsProvider ExecuteShellCommand · test · high · {"product":"linux","category":"process_creation"}
- Audit CVE Event · test · critical · {"product":"windows","service":"application"}
- Malicious Driver Load · test · high · {"product":"windows","category":"driver_load"}
- Malicious Driver Load By Name · test · medium · {"product":"windows","category":"driver_load"}
- Vulnerable Driver Load · test · high · {"product":"windows","category":"driver_load"}
- Vulnerable Driver Load By Name · test · low · {"product":"windows","category":"driver_load"}
- Process Explorer Driver Creation By Non-Sysinternals Binary · test · high · {"product":"windows","category":"file_event"}
- Process Monitor Driver Creation By Non-Sysinternals Binary · test · medium · {"product":"windows","category":"file_event"}
- HKTL - SharpSuccessor Privilege Escalation Tool Execution · experimental · high · {"category":"process_creation","product":"windows"}
- HackTool - SysmonEOP Execution · test · critical · {"category":"process_creation","product":"windows"}
- Suspicious Spool Service Child Process · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1068 Exploitation for Privilege Escalation
MATCH(exploit_mitigation_alert OR known_local_exploit_signature) -> ALERT; SEQUENCE(unprivileged_process, privileged_child_process) WITHIN 1m -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0514 Detection Strategy for Exploitation for Privilege Escalation
AN1419 Analytic 1419
Detects exploitation attempts targeting vulnerable kernel drivers or OS components, often followed by unusual process or token behavior.
AN1420 Analytic 1420
Detects escalation via vulnerable setuid binaries or kernel modules, often chained with unusual access to /proc/kallsyms or /dev/kmem.
AN1421 Analytic 1421
Detects use of vulnerable kernel extensions or entitlements abused via setuid or AppleScript injection chains.
AN1422 Analytic 1422
Detects container breakout behavior via exploitation (e.g., DirtyPipe, CVE-2022-0847), followed by host OS interaction or escalated capability assignment.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Turla · G0010
- APT29 · G0016
- Threat Group-3390 · G0027
- FIN6 · G0037
- OilRig · G0049
- APT32 · G0050
- FIN8 · G0061
- APT33 · G0064
- PLATINUM · G0068
- Cobalt Group · G0080
- Whitefly · G0107
- HAFNIUM · G0125
- ZIRCONIUM · G0128
- Tonto Team · G0131
- BITTER · G1002
- LAPSUS$ · G1004
- Scattered Spider · G1015
- Volt Typhoon · G1017
- MoustachedBouncer · G1019
- BlackByte · G1043
- UNC3886 · G1048
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.