1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1404 Exploitation for Privilege Escalation — Detection Rules

Detection workspace for T1404 Exploitation for Privilege Escalation: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

No reviewed association in this snapshot.

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0665 Detection of Exploitation for Privilege Escalation

AN1758 Analytic 1758

From the defender’s perspective, this strategy correlates signals that a previously unprivileged Android app or process has gained higher privileges through exploitation rather than normal OS or MDM flows. Observable behaviors include: (1) unprivileged app processes issuing sensitive syscalls or accessing privileged device interfaces, (2) bursts of SELinux denials followed by an unexpected domain or permission change, (3) creation of new processes running with system or root UID whose lineage traces back to an app sandbox path, and (4) crashes or abnormal restarts of privileged system services followed shortly by a new connection or binder interaction from the same low-privileged app. The focus is on unusual privilege transitions, anomalous process ancestry, and OS security policy violations, not on specific exploit binaries or CVE signatures.

AN1759 Analytic 1759

Correlates app sandbox escape attempts via unsigned binary execution, mmap memory permission changes (RWX), and sandbox profile violations. Detection chain includes app leveraging JIT/JSC to execute shellcode or triggering kernel exploit via crafted IOKit or Mach port abuse.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1404 simulation workspace

No reviewed association in this snapshot.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.