logo

Intruder Tactics: Privilege Escalation

ID: d70702da-205a-5b48-a6dc-08ced2a6bd1d

STIX ID: report--d70702da-205a-5b48-a6dc-08ced2a6bd1d

Feed Name: Binary Defense Blog

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

This document outlines what privilege escalation is, describes common attacker scenarios (local privilege escalation, exploitation to elevate to SYSTEM or local administrator, and progression to Domain Administrator), highlights tools and behaviours attackers use (mimikatz, Bloodhound), and recommends mitigations and monitoring steps such as enabling Credential Guard, restricting SeDebugPrivilege, and alerting on anomalous LDAP/file activity and Domain Administrators group changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.