Standard User
To Something Else, Fast.
Group membership changes, token manipulation, UAC bypass, and every other way a standard account ends up acting like an administrator. Triage from what changed to what it was used for. For the AD-specific techniques behind many of these (Kerberoasting, delegation abuse, and the rest), see ADPATH; for the persistence keys a confirmed escalation often leaves behind, see the Registry Key Quick Reference.
Alert Overview
Escalation happens through a handful of well-worn paths. Knowing which one fired tells you where to look next.
Common Trigger Sources
Group Membership Change An account added to Domain Admins, local Administrators, or another privileged group └── Usually the loudest and easiest signal, and the one with the clearest audit trail (Event ID 4728/4732/4756) Token Manipulation / Impersonation [T1134.001] A process duplicating or impersonating a token belonging to a higher-privilege account └── Underlies techniques like SeImpersonatePrivilege abuse and the Potato-family exploits UAC Bypass [T1548.002] A known technique (fodhelper.exe, eventvwr.exe registry hijack, and similar) used to run elevated without a consent prompt └── Signature-detectable by most EDR, since the technique list is well-documented and finite Linux / sudo Abuse [T1548.001] Misconfigured sudoers entries, SUID binary abuse, or a kernel exploit used to reach root // same underlying question across all four: did a lower-privilege actor gain a higher-privilege context, and was it used
Initial Triage Steps
Confirm what happened before deciding whether it matters.
Five Checks, In Order
1. Identify exactly what escalated A group membership change, a token/impersonation event, a specific UAC bypass signature, or a LOLBin/tool signature tied to a known privesc technique 2. Identify who or what performed it The account involved, and whether it was already privileged or a standard user suddenly acting with elevated rights 3. Check the timeline Was this preceded by an initial-access alert or lateral movement on the same host, or is it isolated └── Escalation rarely happens first; it's usually step two or three of something already underway 4. Check whether the new privilege was actually used Did the account or process go on to touch something only the new privilege level allows, or did it get flagged and stop there 5. Check against known change process A ticket, a change window, or an admin's own documented action can close this out fast
True Positive Indicators
Signals that separate a real escalation from routine administration.
Unapproved Group Membership Change
Known Token Manipulation Technique
UAC Bypass Signature Fired
Elevated Context Was Used
Follows An Existing Alert On The Same Host
False Positive Indicators
Legitimate administration looks a lot like escalation from the outside.
Documented Administrative Change
Legitimate Installer Requesting Elevation
Security Tooling Doing Its Job
Scheduled Task Under A Documented Context
Escalation Criteria
When a privilege escalation alert becomes an active-compromise investigation.
Any Unapproved Privileged Change
Chained With Lateral Movement Or Credential Access
High-Value Target Gained Privilege
Containment Actions
Undo the privilege, then figure out what it was used for while it was there.