Browse Rules

Search and filter across all detection sources

1,267 rules

sagan medium other

[CROWDSTRIKE] Possible Privilege Escalation Detected - Process Escalated Privileges Possible Access Control Bypass

[CROWDSTRIKE] Possible Privilege Escalation Detected - Process Escalated Privileges Possible Access Control Bypass

panther high python

Slack User Privilege Escalation

Detects when a Slack user gains escalated privileges

sagan critical other

[CROWDSTRIKE] Privilege Escalation Tactic Catchall

[CROWDSTRIKE] Privilege Escalation Tactic Catchall

sagan informational other

[SOPHOS] Privilege escalation exploit resolved

[SOPHOS] Privilege escalation exploit resolved

sagan critical other

[CROWDSTRIKE] Possible Privilege Escalation - A user received new privileges.

[CROWDSTRIKE] Possible Privilege Escalation - A user received new privileges.

sagan medium other

[CROWDSTRIKE] Possible Privilege Escalation Detected - Endpoint Received New Privileges

[CROWDSTRIKE] Possible Privilege Escalation Detected - Endpoint Received New Privileges

sagan medium other

[CROWDSTRIKE] Possible Privilege Escalation Detected - Azure Service Principal Received New Privileges

[CROWDSTRIKE] Possible Privilege Escalation Detected - Azure Service Principal Received New Privileges

sagan critical other

[CITRIX] Possible Privilege Escalation - Restricted Shell Bypass

[CITRIX] Possible Privilege Escalation - Restricted Shell Bypass

sagan informational other

[SOPHOS] We prevented a privilege escalation exploit

[SOPHOS] We prevented a privilege escalation exploit

signature-base unknown yara

HKTL_RedSun_Privilege_Escalation_Apr26 [yara]

Detects RedSun hacktool used for privilege escalation through Microsoft Defender.

elastic-protections high eql

Privilege Escalation via SeImpersonatePrivilege

Identifies a privilege escalation attempt from an account with the SeImpersonatePrivilege to full System privileges.

panther high python

GCP.Privilege.Escalation.By.Deployments.Create

Detects privilege escalation in GCP by taking over the deploymentsmanager.deployments.create permission

panther high python

Databricks Potential Privilege Escalation

Detects potential privilege escalation through high volume permission modifications (≥25 per hour) by the same user. Monitors various permission-related actions across account, workspace, and Unity Catalog.

panther medium python

Admin Role Assigned

Assigning an admin role manually could be a sign of privilege escalation

sagan high other

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ARTIFACT (CVE-2021-4034)

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ARTIFACT (CVE-2021-4034)

sagan high other

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ARTIFACT (CVE-2021-4034)

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ARTIFACT (CVE-2021-4034)

sagan high other

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

sagan high other

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

panther informational python

GCP Privileged Operation

Detects privileged operations in GCP that could be part of a privilege escalation attempt, especially when following tag binding creation.

chronicle unknown yara-l

trickbot_behaviour_privilege_escalation_attack

Detects \

panther medium python

AWS Privilege Escalation Via User Compromise

sagan high other

[LINUX-POLKIT] POSSIBLE POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

[LINUX-POLKIT] POSSIBLE POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

sagan high other

[LINUX-POLKIT] POSSIBLE POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

[LINUX-POLKIT] POSSIBLE POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

elastic-protections high eql

Potential Privilege Escalation via Rogue WinRM

Identifies a privilege escalation attempt via impersonation using RogueWinRM. RogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if the WinRM service is not running.

mdecrevoisier high sigma

SQL server sqlcmd utility abuse for privilege escalation

Detects scenarios where an attacker uses sqlcmd utility to escalate privileges or introduce weaknesses.