mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
initial commit
This commit is contained in:
@@ -0,0 +1,20 @@
|
||||
|||
|
||||
|--|-----|
|
||||
|**ID**|**M9013**|
|
||||
|
||||
# Privilege Escalation #
|
||||
Behaviors that aim to obtain a higher level of permission.
|
||||
|
||||
* **Application Shimming** [T1138](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/app-shimming.md)
|
||||
* **Bypass User Account Control** [T1088](https://github.com/MAECProject/malware-behaviors/blob/master/defense-evasion/bypass-user-acct-cntl.md)
|
||||
* **DLL Search Order Hijacking** [T1038](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/dll-search-order-hijack.md)
|
||||
* **Exploitation for Privilege Escalation** [T1068](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/exploit-priv-escalate.md)
|
||||
* **File System Permissions Weakness** [T1044](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/file-system-perm-weakness.md)
|
||||
* **Hooking** [E1179](https://github.com/MAECProject/malware-behaviors/blob/master/credential-access/hooking.md)
|
||||
* **Image File Execution Options Injection** [T1183](https://github.com/MAECProject/malware-behaviors/blob/master/defense-evasion/image-file-exe-opt-inj.md)
|
||||
* **Launch Daemon** [T1160](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/launch-daemon.md)
|
||||
* **New Service** [T1050](https://github.com/MAECProject/malware-behaviors/blob/master/persistence/new-service.md)
|
||||
* **Process Injection** [T1055](https://github.com/MAECProject/malware-behaviors/blob/master/defense-evasion/process-inject.md)
|
||||
* **Scheduled Task** [T1053](https://github.com/MAECProject/malware-behaviors/blob/master/execution/scheduled-task.md)
|
||||
* **Setuid and Setgid** [T1166](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/setuid-setgid.md)
|
||||
* **Sudo** [T1169](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/sudo.md)
|
||||
@@ -0,0 +1,11 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1138**|
|
||||
|**Objective(s)**|[Persistence](https://github.com/MAECProject/malware-behaviors/tree/master/persistence), [Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|
||||
|**Related ATT&CK Technique(s)**|[Application Shimming](https://attack.mitre.org/techniques/T1138)|
|
||||
|
||||
Application Shimming
|
||||
====================
|
||||
Malware may use Windows Application Compatibility Infrastructure/Framework (application shim) to elevate privileges or install programs.
|
||||
|
||||
**See ATT&CK Technique:** [**Application Shimming**](https://attack.mitre.org/techniques/T1138).
|
||||
@@ -0,0 +1,11 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1038**|
|
||||
|**Objective(s)**|[Defense Evasion](https://github.com/MAECProject/malware-behaviors/tree/master/defense-evasion), [Persistence](https://github.com/MAECProject/malware-behaviors/tree/master/persistence), [Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|
||||
|**Related ATT&CK Technique(s)**|[DLL Search Order Hijacking](https://attack.mitre.org/techniques/T1038)|
|
||||
|
||||
DLL Search Order Hijacking
|
||||
==========================
|
||||
Malware may place a malicious DLL with the same name as a legitimate, but ambiguously specified, DLL in a location that Windows searches before the legitimate DLL (called a binary planting attack).
|
||||
|
||||
**See ATT&CK Technique:** [**DLL Search Order Hijacking**](https://attack.mitre.org/techniques/T1038).
|
||||
@@ -0,0 +1,11 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1068**|
|
||||
|**Objective(s)**|[Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|
||||
|**Related ATT&CK Technique(s)**|[Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068)|
|
||||
|
||||
Exploitation for Privilege Escalation
|
||||
=====================================
|
||||
Malware may exploit a software vulnerability to escalate privileges.
|
||||
|
||||
**See ATT&CK Technique:** [**Exploitation for Privilege Escalation**](https://attack.mitre.org/techniques/T1068).
|
||||
@@ -0,0 +1,11 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1044**|
|
||||
|**Objective(s)**|[Persistence](https://github.com/MAECProject/malware-behaviors/tree/master/persistence), [Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|
||||
|**Related ATT&CK Technique(s)**|[File System Permissions Weakness](https://attack.mitre.org/techniques/T1044)|
|
||||
|
||||
File System Permissions Weakness
|
||||
================================
|
||||
Malware may exploit a software vulnerability to escalate privileges.
|
||||
|
||||
**See ATT&CK Technique:** [**File System Permissions Weakness**](https://attack.mitre.org/techniques/T1044).
|
||||
@@ -0,0 +1,11 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1160**|
|
||||
|**Objective(s)**|[Persistence](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation), [Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|
||||
|**Related ATT&CK Technique(s)**|[Launch Daemon](https://attack.mitre.org/techniques/T1160)|
|
||||
|
||||
Launch Daemon
|
||||
=============
|
||||
Malware may install a new MacOS launch daemon that can be configured to execute at startup.
|
||||
|
||||
**See ATT&CK Technique:** [**Launch Daemon**](https://attack.mitre.org/techniques/T1160).
|
||||
@@ -0,0 +1,11 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1166**|
|
||||
|**Objective(s)**|[Persistence](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation), [Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|
||||
|**Related ATT&CK Technique(s)**|[Setuid and Setgid](https://attack.mitre.org/techniques/T1166)|
|
||||
|
||||
Setuid and Setgid
|
||||
=================
|
||||
Malware may take advantage of setuid or setgid bits in Linux or macOS applications to elevate privilege or for persistence.
|
||||
|
||||
**See ATT&CK Technique:** [**Setuid and Setgid**](https://attack.mitre.org/techniques/T1166).
|
||||
@@ -0,0 +1,11 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1169**|
|
||||
|**Objective(s)**|[Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|
||||
|**Related ATT&CK Technique(s)**|[Sudo](https://attack.mitre.org/techniques/T1169)|
|
||||
|
||||
Sudo
|
||||
====
|
||||
Malware may take advantage of the sudoers file in Linux or macOS for privilege escalation.
|
||||
|
||||
**See ATT&CK Technique:** [**Sudo**](https://attack.mitre.org/techniques/T1169).
|
||||
Reference in New Issue
Block a user