Intruder Tactics: Privilege Escalation
ID: d70702da-205a-5b48-a6dc-08ced2a6bd1d
STIX ID: report--d70702da-205a-5b48-a6dc-08ced2a6bd1d
Feed Name: Binary Defense Blog
This document outlines what privilege escalation is, describes common attacker scenarios (local privilege escalation, exploitation to elevate to SYSTEM or local administrator, and progression to Domain Administrator), highlights tools and behaviours attackers use (mimikatz, Bloodhound), and recommends mitigations and monitoring steps such as enabling Credential Guard, restricting SeDebugPrivilege, and alerting on anomalous LDAP/file activity and Domain Administrators group changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
