All playbooks
Alert response · Privilege Escalation responders
Privilege escalation
An attempt to gain rights the account did not have, or to run inside a process that already had them.
Assume it worked. What matters now is what the new rights reach, not whether the technique succeeded.
What this does not establish
- Whether it succeeded. Attempts and successes look alike in most logs.
- What the rights were used for. Escalation is a means; the next step is the incident.
- Whether the account was already privileged. Check before assuming a gain.
0 of 9 ticked
Selected step
DetectStep 1 of 9
Identify the source account and target context
- From what, to what — both halves, or the finding has no scope.
- SYSTEM on a laptop and SYSTEM on a domain controller are different incidents.
- For injection, the target process is the prize. Name it.
- Start the timeline now: every action, who took it, when.