1200KM / simulation
T1068 Exploitation for Privilege Escalation — Attack Simulation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will…
Technique description
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Scattered Spider BYOVD (CVE-2015-2291 for Intel Ethernet Diagnostics Driver)
Procedure 1c9ef3e6-bde6-402c-83bc-d89ea8bfd372; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Turla Snake Malware Privilege Escalation Through VM Driver
Procedure 97f621a5-851c-484f-b784-4a9c475006ec; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Turla · G0010
- APT29 · G0016
- Threat Group-3390 · G0027
- FIN6 · G0037
- OilRig · G0049
- APT32 · G0050
- FIN8 · G0061
- APT33 · G0064
- PLATINUM · G0068
- Cobalt Group · G0080
- Whitefly · G0107
- HAFNIUM · G0125
- ZIRCONIUM · G0128
- Tonto Team · G0131
- BITTER · G1002
- LAPSUS$ · G1004
- Scattered Spider · G1015
- Volt Typhoon · G1017
- MoustachedBouncer · G1019
- BlackByte · G1043
- UNC3886 · G1048
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.