Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Privilege Escalation/ T1068

T1068Exploitation for Privilege Escalation

T1068 — Exploitation for Privilege Escalation is a MITRE ATT&CK technique in the Privilege Escalation tactic. Clankerusecase tracks 73 detection use cases covering it and 27 threat-intel articles citing it.

Privilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
73Use cases
27Articles
0Sub-techniques
1Tactic

Use cases covering this technique (73)

[WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Internal exploit · alerting DSPDD [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Internal exploit · alerting DSPDD [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) Internal exploit · alerting DSPDD [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Internal exploit · alerting DSPDDCW [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD Child Processes of Spoolsv exe ESCU actions · alerting P Cisco Isovalent - Kprobe Spike ESCU actions · hunting P Detect Baron Samedit CVE-2021-3156 ESCU actions · alerting P Detect Baron Samedit CVE-2021-3156 Segfault ESCU actions · alerting P Detect Baron Samedit CVE-2021-3156 via OSQuery ESCU actions · alerting P First Time Seen Child Process of Zoom ESCU actions · hunting P Linux Auditd Copy Fail Privilege Escalation ESCU actions · alerting P Linux Binary Launched Process with Null Argv ESCU actions · alerting P Linux Malformed Auth Entry ESCU actions · hunting P Linux PF_ALG Registration Outside of Boot Window ESCU actions · alerting P Linux pkexec Privilege Escalation ESCU actions · alerting P Linux Suspicious Namespace Creation ESCU actions · alerting P Spoolsv Suspicious Process Access ESCU actions · alerting P Windows Driver Inventory ESCU actions · hunting P Windows Driver Load Non-Standard Path ESCU actions · alerting P Windows Drivers Loaded by Signature ESCU actions · hunting P Windows MSI Rollback Script Deleted By Non-Msiexec Process ESCU actions · alerting P Windows Potato Privilege Escalation Tool Execution ESCU actions · alerting P Windows Privilege Escalation Attempt Via MSI Rollback ESCU actions · alerting P Windows Privilege Escalation Suspicious Process Elevation ESCU actions · alerting P Windows Privilege Escalation System Process Without System Parent ESCU actions · alerting P Windows Privilege Escalation User Process Spawn System Process ESCU actions · alerting P Windows Remote Image Load ESCU actions · hunting P Windows Service Create Kernel Mode Driver ESCU actions · alerting P Windows System File on Disk ESCU actions · hunting P Microsoft SharePoint Server Elevation of Privilege ESCU actions · hunting P VMWare Aria Operations Exploit Attempt ESCU actions · alerting P [LLM] eBPF program load or pinned object created from non-system parent on Arch host Bespoke install · hunting DSΣPDDCS [LLM] Budibase CVE-2026-48150: POST /api/public/v1/roles/assign with global builder/admin grant in body Bespoke exploit · alerting SΣPDD [LLM] Budibase audit log: builder.global / admin.global granted to user by non-global caller Bespoke actions · alerting SPDD [LLM] Budibase: rapid bulk POSTs to /api/public/v1/roles/assign from single source Bespoke actions · alerting SPDD [LLM] Budibase: API key minted via /api/global/self/api_key then /api/public/v1/roles/assign within 5m Bespoke exploit · alerting SPDD [LLM] Atomic Arch rootkit — eBPF program load by AUR-build-chain descendant Bespoke install · hunting DSPDD [LLM] CTFMON spawning elevated child or CTFMON-hosted privilege escalation (CVE-2026-45586 / GreenPlasma) Bespoke exploit · alerting DSΣPDDCS [LLM] PoC artefact drop — Chaotic Eclipse named exploits (YellowKey, GreenPlasma, MiniPlasma, RoguePlanet, bitskrieg) Bespoke install · hunting DSΣPDDCS [LLM] Defender Component (MsMpEng/NisSrv) Spawns Interactive Shell with SYSTEM Integrity Bespoke exploit · alerting DSΣPDDCS [LLM] Unpatched Assets Vulnerable to Chaotic Eclipse Defender CVE Cluster Bespoke recon · hunting DSP [LLM] Hosts missing June 2026 Patch Tuesday critical RCE/EoP fixes Bespoke weapon · hunting DSP [LLM] csrss.exe or dwm.exe spawning child process (Win32K-GRFX kernel exploit marker) Bespoke exploit · alerting DSΣPDDCS [LLM] Hyper-V worker process (vmwp.exe / vmms.exe) spawning unexpected child (guest-to-host escape) Bespoke exploit · alerting DSΣPDDCS [LLM] nebula-mesh CVE-2026-47724 — cross-operator admin API key mint via POST /api/v1/operators/{id}/api-keys Bespoke exploit · alerting SΣPDD [LLM] Unprivileged user namespace + nf_tables manipulation chain (CVE-2026-23111 exploitation) Bespoke exploit · alerting DSPDDCS [LLM] nft (nftables) ruleset manipulation by non-root account on Linux endpoints Bespoke exploit · hunting DSΣPDDCS [LLM] HTTP access to Shopper admin team-settings / Livewire endpoints (CVE-2026-47744) Bespoke exploit · hunting DSΣPDDCW [LLM] Privileged or root pod created by Jupyter Enterprise Gateway ServiceAccount Bespoke install · alerting SΣPDDCW [LLM] Enterprise Gateway service account creates Jupyter kernel pod as root (CVE-2026-44180 outcome) Bespoke exploit · alerting SPDDCW [LLM] praisonai-platform: POST /workspaces/*/members with role=owner (CVE-2026-47413) Bespoke exploit · hunting DSΣPDD [LLM] Container escape via cgroups release_agent write (CVE-2022-0492) Bespoke exploit · alerting DSΣPDDCS [LLM] praisonai-platform CVE-2026-47416: PATCH /workspaces/{id}/members/{user_id} role-change request Bespoke exploit · hunting SΣPDD [LLM] PraisonAI Python subprocess spawns OS shell with discovery / credential-reading commands Bespoke exploit · alerting DSPDDCS [LLM] Literal PraisonAI sandbox-escape signature: `print.__self__` + builtins dict access Bespoke exploit · alerting DSΣPDDCS [LLM] Node.js process spawns shell or LOLBin — vm2 sandbox escape post-exploitation (CVE-2026-47210) Bespoke exploit · alerting DSΣPDDCS [LLM] node.exe spawning child_process targets — vm2 Promise species sandbox escape post-exploitation Bespoke exploit · alerting DSΣPDDCS [LLM] vm2 Promise species sandbox escape PoC fingerprint in scripts/command lines Bespoke weapon · hunting DSPDDCS [LLM] Node.exe spawning OS shell after vm2 sandbox exploitation Bespoke install · alerting DSΣPDDCS [LLM] Container privilege escalation via Looney Tunables, PwnKit, sudo chroot Bespoke exploit · alerting DSΣPDDCS [LLM] Nezha CVE-2026-46716 exploit: POST /api/v1/cron with empty servers + CronCoverAll Bespoke exploit · alerting SΣPDD [LLM] MLflow server process spawning Claude Code CLI or shell — CVE-2026-2611 RCE chain Bespoke exploit · alerting DSΣPDDCS [LLM] utcp-cli command injection via UTCP_ARG substitution in python→bash -c CMD_N_OUTPUT script Bespoke exploit · alerting DSΣPDD [LLM] Portainer Swarm service spec with elevated Linux capabilities or unconfined Seccomp Bespoke exploit · alerting DSΣPDDCS [LLM] Portainer plugin management API access (CVE-2026-44848) Bespoke exploit · alerting SΣPDD [LLM] Docker plugin runtime spawned from /var/lib/docker/plugins/ on host (CVE-2026-44848) Bespoke install · alerting DSΣPDDCS [LLM] Docker daemon plugin install/enable event from non-admin context (CVE-2026-44848) Bespoke install · hunting SPDD [LLM] FlowiseAI POST /api/v1/node-custom-function with NodeVM Sandbox-Escape Payload (CVE-2026-46442) Bespoke exploit · alerting SΣPDD [LLM] CVE-2022-26923 exploitation via update6.exe binary execution Bespoke exploit · alerting DSΣPDDCS [LLM] BYOVD: Genshin Impact mhyprot.sys driver dropped/loaded outside legitimate game install (Embargo evil-mhyprot-cli) Bespoke install · alerting DSΣP

Articles citing this technique (27)