H3AD-REF / PLAYBOOKS / PRIVILEGE ESCALATION ALERT

Standard User
To Something Else, Fast.

Group membership changes, token manipulation, UAC bypass, and every other way a standard account ends up acting like an administrator. Triage from what changed to what it was used for. For the AD-specific techniques behind many of these (Kerberoasting, delegation abuse, and the rest), see ADPATH; for the persistence keys a confirmed escalation often leaves behind, see the Registry Key Quick Reference.

Alert Overview

Escalation happens through a handful of well-worn paths. Knowing which one fired tells you where to look next.

Common Trigger Sources

Group Membership Change
An account added to Domain Admins, local Administrators, or another privileged group
└── Usually the loudest and easiest signal, and the one with the clearest audit trail (Event ID 4728/4732/4756)

Token Manipulation / Impersonation [T1134.001]
A process duplicating or impersonating a token belonging to a higher-privilege account
└── Underlies techniques like SeImpersonatePrivilege abuse and the Potato-family exploits

UAC Bypass [T1548.002]
A known technique (fodhelper.exe, eventvwr.exe registry hijack, and similar) used to run elevated
without a consent prompt
└── Signature-detectable by most EDR, since the technique list is well-documented and finite

Linux / sudo Abuse [T1548.001]
Misconfigured sudoers entries, SUID binary abuse, or a kernel exploit used to reach root
    // same underlying question across all four: did a lower-privilege actor gain a higher-privilege context, and was it used

Initial Triage Steps

Confirm what happened before deciding whether it matters.

Five Checks, In Order

1. Identify exactly what escalated
A group membership change, a token/impersonation event, a specific UAC bypass signature, or a
LOLBin/tool signature tied to a known privesc technique

2. Identify who or what performed it
The account involved, and whether it was already privileged or a standard user suddenly acting
with elevated rights

3. Check the timeline
Was this preceded by an initial-access alert or lateral movement on the same host, or is it isolated
└── Escalation rarely happens first; it's usually step two or three of something already underway

4. Check whether the new privilege was actually used
Did the account or process go on to touch something only the new privilege level allows, or did it
get flagged and stop there

5. Check against known change process
A ticket, a change window, or an admin's own documented action can close this out fast

True Positive Indicators

Signals that separate a real escalation from routine administration.

TRUE POSITIVE

Unapproved Group Membership Change

No ticket, no approval, no explanation on file
A privileged group membership change with nothing in the change management system to account for it is close to worst-case by default, regardless of what else is or isn't present.
TRUE POSITIVE

Known Token Manipulation Technique

A named technique, not a generic anomaly
A signature match for SeImpersonatePrivilege abuse, a Potato-family exploit, or a similar documented token-manipulation technique, rather than a vague "unusual token activity" heuristic.
TRUE POSITIVE

UAC Bypass Signature Fired

A specific, well-documented technique
A detection matching a known UAC bypass method, such as the fodhelper.exe or eventvwr.exe registry-hijack techniques, run without a corresponding user-approved consent prompt.
TRUE POSITIVE

Elevated Context Was Used

The privilege didn't just exist, it did something
The newly escalated account or process went on to touch something sensitive shortly after, like LSASS, a domain controller, or backup infrastructure.
TRUE POSITIVE

Follows An Existing Alert On The Same Host

Escalation as a step, not an isolated event
The escalation attempt follows a known initial-access, exploitation, or lateral-movement alert on the same host within a short window, which is the normal shape of a real intrusion chain.

False Positive Indicators

Legitimate administration looks a lot like escalation from the outside.

FALSE POSITIVE

Documented Administrative Change

A ticket closes this out immediately
The group membership change or elevation matches a documented, ticketed administrative action, with a named approver and a business reason on record.
FALSE POSITIVE

Legitimate Installer Requesting Elevation

A UAC prompt an actual admin approved
Standard software installation that correctly requests elevation, and where the consent prompt was seen and approved by a real administrator at the keyboard.
FALSE POSITIVE

Security Tooling Doing Its Job

A scanner checking for exactly this kind of weakness
A known vulnerability scanner or security tool performing privilege checks as part of its normal function, which can trigger the same detections a real attack would.
FALSE POSITIVE

Scheduled Task Under A Documented Context

Automation, not an attacker
An automated administrative task running under a service account with a documented, pre-approved elevated context, firing on its normal schedule.

Escalation Criteria

When a privilege escalation alert becomes an active-compromise investigation.

ESCALATE

Any Unapproved Privileged Change

Treat as worst-case until proven otherwise
An unapproved privileged group membership change escalates immediately by default. The burden is on finding a legitimate explanation, not on ruling out malicious intent first.
ESCALATE

Chained With Lateral Movement Or Credential Access

Not an isolated event anymore
Escalation combined with lateral movement or credential-access indicators on the same host or account gets treated as active compromise, not a standalone privesc alert to close individually.
ESCALATE

High-Value Target Gained Privilege

Domain controllers and backup infrastructure are never routine
A domain controller, backup server, or similarly high-value system is the one where the privilege change occurred, regardless of how minor the change itself looks in isolation.

Containment Actions

Undo the privilege, then figure out what it was used for while it was there.

CONTAIN

Remove The Privilege Immediately

The fastest, most direct containment step available
Pull the account out of the privileged group or revoke the elevated token immediately, before doing anything else. This alone stops most of the ongoing risk.
CONTAIN

Isolate The Host

Where the escalation technique actually ran
Isolate the host where the escalation occurred from the network, without powering it off, to preserve evidence while stopping further action from that machine.
CONTAIN

Rotate Reachable Credentials

Assume the elevated window was used for more than the escalation itself
Rotate credentials for the account involved and any other accounts it could have touched during the window it held elevated privilege.
CONTAIN

Hunt For The Same Technique Environment-Wide

One confirmed hit usually isn't the only attempt
Search for the same escalation technique or tool signature across the rest of the environment, since a working technique is rarely tried against only one host.