Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Privilege Escalation/ T1548

T1548Abuse Elevation Control Mechanism

T1548 — Abuse Elevation Control Mechanism is a MITRE ATT&CK technique in the Privilege Escalation tactic. Clankerusecase tracks 21 detection use cases covering it and 3 threat-intel articles citing it.

Privilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
21Use cases
3Articles
6Sub-techniques
1Tactic

Sub-techniques (6)

Use cases covering this technique (21)

AWS IAM AdministratorAccess policy applied to a user Internal install · alerting DDCW Azure AD member assigned Global Administrator role Internal install · alerting DD Kubernetes pod created with privileged flag Internal install · alerting DD [WEEKLY] Public-facing app auth/authz bypass into server-side code execution (patch-bypass wave) Internal exploit · alerting DSΣPDDCS Allow Operation with Consent Admin ESCU actions · alerting P Linux Persistence and Privilege Escalation Risk Behavior ESCU actions · alerting P Linux Telnet Authentication Bypass ESCU actions · alerting P Services Escalate Exe ESCU actions · alerting P Windows Privilege Escalation Suspicious Process Elevation ESCU actions · alerting P Windows Privilege Escalation System Process Without System Parent ESCU actions · alerting P Windows Privilege Escalation User Process Spawn System Process ESCU actions · alerting P Splunk Edit User Privilege Escalation ESCU actions · hunting P Splunk Enterprise KV Store Incorrect Authorization ESCU actions · hunting P Splunk risky Command Abuse disclosed february 2023 ESCU actions · hunting P Splunk Unauthorized Notification Input by User ESCU actions · hunting P [LLM] ApostropheCMS SSPP payload: $pullAll/__proto__ PATCH to piece-type API (CVE-2026-53609) Bespoke exploit · alerting SΣP [LLM] ApostropheCMS auth-bypass symptom: protected piece-type endpoint 401/403 → 200 transition Bespoke actions · hunting SP [LLM] ApostropheCMS exploit chain: unauth PATCH to /@apostrophecms/global → 200 GET on /user within 30s Bespoke exploit · alerting SP [LLM] IdP self-registration or profile email-change asserting a privileged Budibase user's email Bespoke actions · hunting SP [LLM] FileBrowser proxy-auth header forgery naming admin on /api/login Bespoke exploit · alerting SΣPDD [LLM] FileBrowser post-bypass admin API actions (DELETE/PUT /api/users, /api/settings) Bespoke actions · hunting SΣP

Articles citing this technique (3)