Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

All playbooks

Alert response · Privilege Escalation responders

Privilege escalation

An attempt to gain rights the account did not have, or to run inside a process that already had them.

Assume it worked. What matters now is what the new rights reach, not whether the technique succeeded.

What this does not establish

  • Whether it succeeded. Attempts and successes look alike in most logs.
  • What the rights were used for. Escalation is a means; the next step is the incident.
  • Whether the account was already privileged. Check before assuming a gain.

0 of 9 ticked

Selected step

DetectStep 1 of 9

Identify the source account and target context

  • From what, to what — both halves, or the finding has no scope.
  • SYSTEM on a laptop and SYSTEM on a domain controller are different incidents.
  • For injection, the target process is the prize. Name it.
  • Start the timeline now: every action, who took it, when.