Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Privilege Escalation/ T1068

T1068Exploitation for Privilege Escalation

T1068 — Exploitation for Privilege Escalation is a MITRE ATT&CK technique in the Privilege Escalation tactic. Clankerusecase tracks 75 detection use cases covering it and 17 threat-intel articles citing it.

Privilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
75Use cases
17Articles
0Sub-techniques
1Tactic

Use cases covering this technique (75)

[WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Internal exploit · alerting DSPDD [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Internal exploit · alerting DSPDD [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) Internal exploit · alerting DSPDD [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Internal exploit · alerting DSPDDCW [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD Child Processes of Spoolsv exe ESCU actions · alerting P Cisco Isovalent - Kprobe Spike ESCU actions · hunting P Detect Baron Samedit CVE-2021-3156 ESCU actions · alerting P Detect Baron Samedit CVE-2021-3156 Segfault ESCU actions · alerting P Detect Baron Samedit CVE-2021-3156 via OSQuery ESCU actions · alerting P First Time Seen Child Process of Zoom ESCU actions · hunting P Linux Apparmor Bypass Via Aaexec ESCU actions · alerting P Linux Auditd Copy Fail Privilege Escalation ESCU actions · alerting P Linux Auditd Possible Setuid Execve Privesc ESCU actions · hunting P Linux Binary Launched Process with Null Argv ESCU actions · alerting P Linux Dirty Frag Kernel Privilege Escalation ESCU actions · alerting P Linux Malformed Auth Entry ESCU actions · hunting P Linux Pedit Offset Out Of Bounds ESCU actions · alerting P Linux PF_ALG Registration Outside of Boot Window ESCU actions · alerting P Linux pkexec Privilege Escalation ESCU actions · alerting P Linux Suspicious Namespace Creation ESCU actions · alerting P Spoolsv Suspicious Process Access ESCU actions · alerting P Windows Admin Password Changed by Non-Admin ESCU actions · alerting P Windows Cloud Files Filter Log Created by Non-System Process ESCU actions · alerting P Windows Driver Inventory ESCU actions · hunting P Windows Driver Load Non-Standard Path ESCU actions · alerting P Windows Drivers Loaded by Signature ESCU actions · hunting P Windows MSI Rollback Script Deleted By Non-Msiexec Process ESCU actions · alerting P Windows MsMpEng Writing to System32 ESCU actions · alerting P Windows Non-System Process Querying Definition Update ESCU actions · hunting P Windows Potato Privilege Escalation Tool Execution ESCU actions · alerting P Windows Privilege Escalation Attempt Via MSI Rollback ESCU actions · alerting P Windows Privilege Escalation Suspicious Process Elevation ESCU actions · alerting P Windows Privilege Escalation System Process Without System Parent ESCU actions · alerting P Windows Privilege Escalation User Process Spawn System Process ESCU actions · alerting P Windows Remote Image Load ESCU actions · hunting P Windows Service Create Kernel Mode Driver ESCU actions · alerting P Windows Suspicious Burst of Password Changes ESCU actions · alerting P Windows Suspicious Child Process of TieringEngineService.exe ESCU actions · alerting P Windows Suspicious Defender Engine or Signature Files Created ESCU actions · hunting P Windows Suspicious Defender Update Activity in INetCache ESCU actions · hunting P Windows System File on Disk ESCU actions · hunting P Windows VSSVC Process Accessing Defender Engine ESCU actions · alerting P Microsoft SharePoint Server Elevation of Privilege ESCU actions · hunting P VMWare Aria Operations Exploit Attempt ESCU actions · alerting P Splunk Low-Priv Search as nobody SplunkDeploymentServerConfig App ESCU actions · hunting P [LLM] Cisco FMC www web-service account escalating to root via sudo under /usr/local/sf/bin/ Bespoke exploit · hunting SPDD [LLM] Exposure hunt: ESX/ESXi VM-escape + info-disclosure host flaws (CVE-2026-47876 / CVE-2026-41703 / CVE-2026-41709) Bespoke exploit · hunting DSP [LLM] Firefox/Tor renderer (content) process spawning an unexpected child — sandbox escape / RCE Bespoke exploit · alerting DSΣPDDCS [LLM] Endpoint exposed to GhostLock kernel futex LPE (CVE-2026-43499, IonStack stage 2) Bespoke exploit · hunting DSP [LLM] Self-hosted JFrog Artifactory exposed to OpenAI-credited zero-days CVE-2026-65618/65923/66018 Bespoke exploit · hunting DSP [LLM] Linux core_pattern overwritten to memfd/pipe handler (CVE-2026-53264 privesc payoff) Bespoke install · alerting DSΣPDDCS [LLM] Linux root process executed from memfd (CVE-2026-53264 core-dump payload) Bespoke exploit · alerting DSΣPDDCS [LLM] Unprivileged Linux tc clsact/flower/gact traffic-control manipulation (CVE-2026-53264 trigger) Bespoke exploit · hunting DSΣPDDCS [LLM] CVE-2026-53264 unpatched kernel exposure (traffic-control UAF LPE) Bespoke recon · hunting DSP [LLM] NodeBB admin-panel access via homepage-setting authorization bypass (first-seen admin API) Bespoke exploit · hunting SP [LLM] Gitea PR head-branch update via public base-repo route (CVE-2026-58443) Bespoke exploit · hunting SΣP [LLM] Gitea instances exposed to CVE-2026-58443 (public-only token PR write) Bespoke exploit · hunting DSP [LLM] GentleKiller BYOVD: ThrottleBlood.sys vulnerable driver load (CVE-2025-7771) Bespoke exploit · alerting DSΣPDDCS [LLM] TSDProxy management-port replay: loopback connection to 127.0.0.1:8080 by non-proxy process Bespoke exploit · alerting DSΣPCS [LLM] TSDProxy management API abuse: /api/v1 request with forged x-tsdproxy-id and auth token Bespoke actions · alerting SPDD [LLM] Rancher Manager assets vulnerable to CVE-2026-41052 (PSA privilege-escalation exposure) Bespoke recon · hunting DS [LLM] BYOVD: Genshin Impact mhyprot.sys driver dropped/loaded outside legitimate game install (Embargo evil-mhyprot-cli) Bespoke install · alerting DSΣP [LLM] Dirty Pipe (CVE-2022-0847): /etc/passwd or /etc/shadow modified by unexpected process Bespoke exploit · alerting DSΣPCS [LLM] Dirty Pipe SUID hijack: root-privileged process executing from /tmp or /dev/shm Bespoke exploit · alerting DSΣPDDCS [LLM] Dirty Pipe (CVE-2022-0847) vulnerable kernel exposure inventory Bespoke exploit · hunting DSP [LLM] PwnKit pkexec executed with empty argv (CVE-2021-4034 exploit primitive) Bespoke exploit · alerting DSΣPDDCS [LLM] PwnKit GCONV_PATH artifact directory/file creation Bespoke exploit · alerting DSΣPCS [LLM] Unprivileged user-namespace creation (unshare CLONE_NEWUSER) preceding Linux privilege escalation Bespoke exploit · hunting DSΣPDDCS [LLM] Prototype pollution payload in CLI args (--__proto__ / constructor.prototype) to Node tool Bespoke exploit · alerting DSΣPDDCS [LLM] World-writable executable run as a shell (-c) — minimist polluted shell privesc payload Bespoke install · hunting DSΣPDDCS [LLM] Anonymous principal reaching kubelet/pod proxy subresources (CVE-2018-1002105 tunnel) Bespoke actions · alerting SΣPDDCW [LLM] FTP control-channel connection followed by write to Unix system path (CVE-2018-1315 traversal chain) Bespoke exploit · hunting DSPCS

Articles citing this technique (17)