detecting-t1548-abuse-elevation-control-mechanism - Detecting T1548 Abuse Elevation Control Mechanism
Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation using system logs.
Tags
Updated: 2026-09-15Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Monitor UAC registry modifications
- Detect auto-elevating process abuse
- Track process integrity level changes
- Hunt for elevated process spawning
- Monitor Linux elevation abuse
- Correlate privilege escalation events
Inputs
- Sysmon Event ID 1 logs
- Windows Security Event ID 4688 logs
- UAC registry auditing data
- Sysmon Event ID 12 and 13 logs
- EDR elevation monitoring data
Outputs
- Threat hunting report
- UAC bypass detection alerts
Requirements
- Sysmon with command-line logging
- Windows Event 4688 with process tracking
- Registry auditing for UAC keys
- EDR elevation monitoring capabilities
