Browse Rules

Search and filter across all detection sources

1,033 rules

sagan critical other

[CROWDSTRIKE] Privilege Escalation Tactic Catchall

[CROWDSTRIKE] Privilege Escalation Tactic Catchall

sagan informational other

[SOPHOS] Privilege escalation exploit resolved

[SOPHOS] Privilege escalation exploit resolved

sagan critical other

[CITRIX] Possible Privilege Escalation - Restricted Shell Bypass

[CITRIX] Possible Privilege Escalation - Restricted Shell Bypass

sagan informational other

[SOPHOS] We prevented a privilege escalation exploit

[SOPHOS] We prevented a privilege escalation exploit

signature-base unknown yara

HKTL_RedSun_Privilege_Escalation_Apr26 [yara]

Detects RedSun hacktool used for privilege escalation through Microsoft Defender.

panther high python

GCP.Privilege.Escalation.By.Deployments.Create

Detects privilege escalation in GCP by taking over the deploymentsmanager.deployments.create permission

panther high python

Databricks Potential Privilege Escalation

Detects potential privilege escalation through high volume permission modifications (≥25 per hour) by the same user. Monitors various permission-related actions across account, workspace, and Unity Catalog.

panther medium python

Admin Role Assigned

Assigning an admin role manually could be a sign of privilege escalation

panther high python

Slack User Privilege Escalation

Detects when a Slack user gains escalated privileges

sagan critical other

[CROWDSTRIKE] Possible Privilege Escalation - A user received new privileges.

[CROWDSTRIKE] Possible Privilege Escalation - A user received new privileges.

sagan medium other

[CROWDSTRIKE] Possible Privilege Escalation Detected - Endpoint Received New Privileges

[CROWDSTRIKE] Possible Privilege Escalation Detected - Endpoint Received New Privileges

sagan high other

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ARTIFACT (CVE-2021-4034)

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ARTIFACT (CVE-2021-4034)

sagan high other

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ARTIFACT (CVE-2021-4034)

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ARTIFACT (CVE-2021-4034)

sagan high other

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

sagan high other

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

[LINUX-POLKIT] POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

chronicle unknown yara-l

trickbot_behaviour_privilege_escalation_attack

Detects \

panther medium python

AWS Privilege Escalation Via User Compromise

sagan high other

[LINUX-POLKIT] POSSIBLE POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

[LINUX-POLKIT] POSSIBLE POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

sagan high other

[LINUX-POLKIT] POSSIBLE POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

[LINUX-POLKIT] POSSIBLE POLKIT PRIVILEGE ESCALATION ATTEMPT (CVE-2021-4034)

elastic-protections high eql

Privilege Escalation via SeImpersonatePrivilege

Identifies a privilege escalation attempt from an account with the SeImpersonatePrivilege to full System privileges.

sagan medium other

[CROWDSTRIKE] Possible Privilege Escalation Detected - Azure Service Principal Received New Privileges

[CROWDSTRIKE] Possible Privilege Escalation Detected - Azure Service Principal Received New Privileges

sagan medium other

[CROWDSTRIKE] Possible Privilege Escalation Detected - Executable Written In A Detection Summary Event

[CROWDSTRIKE] Possible Privilege Escalation Detected - Executable Written In A Detection Summary Event

sagan medium other

[CROWDSTRIKE] Possible Privilege Escalation Detected - Process Attempted To Modify TrustedInstaller Service ImagePath

[CROWDSTRIKE] Possible Privilege Escalation Detected - Process Attempted To Modify TrustedInstaller Service ImagePath

sagan medium other

[CROWDSTRIKE] Possible Privilege Escalation Detected - Process Escalated Privileges Possible Access Control Bypass

[CROWDSTRIKE] Possible Privilege Escalation Detected - Process Escalated Privileges Possible Access Control Bypass

signature-base unknown yara

b374k_back_connect [yara]

Detects privilege escalation tool