Threat

Privilege Escalation

Privilege escalation describes the process of gaining higher permissions than an account or process is assigned.

Privilege escalation refers to gaining higher permissions than an account or process is assigned. Attackers use it to change from a normal user to an administrator.

How it works

There are two main types of escalation. Vertical escalation involves an account gaining higher permissions, such as admin or system rights. In horizontal escalation, an attacker takes over another account with a similar privilege level but access to different resources.

Common methods include unpatched vulnerabilities, misconfigured services, excessive permissions, and stored credentials. In cloud environments, roles that can assign themselves more permissions are often exploited.

A practical example

An attacker has access to a standard account. They find a service that runs with system rights and whose program file any user can modify. The attacker replaces the file and restarts the service. They then have system rights on the server. The EDR reports the unusual process, and the SOC isolates the server.

What to look out for

  • Assign permissions based on the principle of least privilege.
  • Patch local vulnerabilities as consistently as internet-facing ones.
  • Check services and scheduled tasks for insecure permissions.
  • Monitor changes to admin groups and cloud roles.
  • Use PAM and just-in-time access for administrative rights.

Why it matters

With normal permissions, the potential damage is usually limited. Only with admin rights can an attacker disable security tools, delete backups or deploy encryption widely. The detection of privilege escalation is therefore an important control point.

Typical mistakes

Many employees often have local admin rights on their laptops 'because it is easier'. This significantly simplifies an attacker's next move. Another common mistake is having unmonitored cloud roles with permission management capabilities.

Relevance for the SOC

New members in admin groups, processes with system rights from unusual paths and role changes are among the most important alerts. They deserve high priority.

How we implement it

We monitor permission changes in Active Directory, Entra ID and cloud roles. We treat suspicious escalations as a high-priority Case.

How ANOMAL implements this