Privilege Escalation threat hunts
22 hunts covering privilege escalation, each with a hypothesis, the queries that test it and what the hunt cannot see.
22 hunts
-
high Part 3 of 3Research by Microsoft
Zimbra secrets theft and cluster propagation
An intruder is using Zimbra administrative utilities to dump service credentials and move laterally to peer nodes using the zimbra service account's SSH identity.
5 query2 analytic1 checkpoint1 action2 taskCVE-2026-73570 -
high Part 2 of 3Research by Microsoft
Zimbra Privilege Escalation and Root Persistence
An intruder has escalated from the Zimbra service account to root by symlinking application logs to PAM configurations and established persistence through a rare systemd service.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-73570 -
high Part 1 of 3Research by Microsoft
Zimbra CVE-2026-73570 RCE and JSP Web Shell Entry
An attacker is exploiting CVE-2026-73570 on internet-facing Zimbra servers to execute commands via the SNMP path and drop JSP web shells in the webroot for persistence.
4 query2 analytic2 checkpoint1 action2 taskCVE-2026-73570 -
highResearch by Unit 42
Kubernetes Operator RBAC Abuse and Secret Theft
A vulnerable or outdated Kubernetes operator is running with excessive ClusterRole permissions, allowing an attacker to exfiltrate cluster-wide secrets or establish unauthorized AI agent bridges to external endpoints.
3 query1 analytic1 checkpoint2 taskCVE-2026-6389 -
highResearch by Rapid7
Windows Zero-Day Privilege Escalation and Ransomware
Adversaries are exploiting unpatched Windows ALPC or Update Stack vulnerabilities to escalate to SYSTEM integrity and deploy ransomware, leaving traces of rare process elevations and specific link-resolution artifacts.
4 query1 analytic1 checkpoint2 taskCVE-2026-81963 · CVE-2026-85880 -
highResearch by Cisco Talos
Microsoft Patch Tuesday September 2026 Exposure
An adversary is exploiting September 2026 zero-day or critical remote code execution vulnerabilities, such as those in DNS Server or the Windows Update Stack, to establish initial access or escalate privileges on unpatched systems.
3 query1 analytic1 checkpoint2 taskCVE-2026-58599 · CVE-2026-65669 -
high Part 3 of 3Research by The DFIR Report
Apache ActiveMQ Lateral Movement and Ransomware Impact
An attacker has transitioned from an exploited ActiveMQ server to lateral movement via RDP using stolen credentials, ultimately deploying LockBit ransomware from user-writable directories or with specific execution flags.
3 query1 analytic1 checkpoint1 action2 taskCVE-2023-46604 -
high Part 1 of 3Research by The DFIR Report
ActiveMQ Exploitation and Metasploit Staging
An intruder has exploited CVE-2023-46604 on an ActiveMQ server to run arbitrary code, staged a Metasploit payload, and escalated to SYSTEM privileges using named pipe impersonation.
4 query2 analytic1 checkpoint1 action2 taskCVE-2023-46604 -
mediumResearch by Elastic Security Labs
Vulnerable Driver Exploitation and Kernel Escalation
An adversary has exploited a public-facing application to stage and load a vulnerable kernel driver, bypassing security controls to gain persistent high-integrity access to the host.
4 query2 analytic2 checkpoint1 action2 taskexecution · initial access · privilege escalation -
highResearch by Elastic Security Labs
AWS Cloud Identity Takeover Chain
An adversary has gained initial access to a cloud account by brute-forcing the console and performing a password reset, then used that access to establish a presence across multiple projects in the organization.
5 query2 analytic1 checkpoint1 action2 taskinitial access · persistence · privilege escalation -
medium Part 2 of 2Research by Unit 42
Endpoint Data Staging and Exfiltration
An adversary has staged sensitive information in temporary directories and is exfiltrating that data via rare outbound network connections or DNS lookups.
3 query1 analytic1 checkpoint1 action2 taskcollection · exfiltration · initial access -
medium Part 1 of 2Research by Unit 42
Identity and Cloud Pivot from Web Exploits
An adversary has exploited an internet-facing web server to establish a beachhead and is now manipulating cloud or SaaS identities to persist and reconfigure the environment.
3 query2 analytic2 checkpoint1 action2 taskcollection · exfiltration · initial access -
highResearch by Elastic Security Labs
Kubernetes Service Account Abuse and Escape
An intruder has harvested a service account token from a compromised pod and is using it to deploy a privileged pod for container escape, bypassing standard runtime process detection.
4 query2 analytic1 checkpoint1 action2 taskcredential access · discovery · execution -
highResearch by Huntress
AD RMS Discovery and Administrative Reconnaissance
An adversary is identifying on-premises AD RMS clusters via DNS and rights-policy template enumeration before escalating privileges via local group membership to reach the administrative surface.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · discovery · privilege escalation -
highResearch by Elastic Security Labs
Linux Local Privilege Escalation Behavior
An intruder is exploiting a kernel vulnerability or a misconfigured SUID helper to transition from a low-privilege foothold in a writable directory to root privileges.
4 query2 analytic1 checkpoint1 action2 taskdiscovery · execution · privilege escalation -
high Part 2 of 2Research by Unit 42
AI-Agentic Escalation and Infrastructure Hijacking
An automated AI agent loop is conducting high-speed privilege escalation via secrets managers, tampering with CI/CD configurations, and hijacking cloud AI endpoints for external orchestration.
4 query1 analytic1 checkpoint1 action2 taskcredential access · impact · initial access -
high Part 1 of 2Research by Unit 42
Automated Service Infiltration and Data Harvesting
An intruder is using autonomous AI agents to breach public web services and map internal microservices while harvesting credentials, leaving behind unique filesystem artifacts and high-frequency network recon patterns.
3 query1 analytic1 checkpoint1 action2 taskcredential access · impact · initial access -
highResearch by Datadog Security Labs
Local Privilege Escalation via Copy-Fail Page Cache Corruption
An unprivileged local attacker exploits CVE-2026-31431 by splicing AF_ALG crypto sockets into the page cache of sensitive system files to achieve root execution without modifying files on disk.
5 query2 analytic1 checkpoint1 action2 taskCVE-2026-31431 -
high Part 2 of 2Research by Volexity
VerdantBamboo Stolen Credential and Pivot Hunt
An adversary has used stolen administrative or service account credentials to access edge appliances via VPN or SSH, subsequently using web-based management interfaces to pivot further or deploy persistence.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 1 of 2Research by Volexity
VERDANTBAMBOO Edge Appliance Post-Exploitation
An adversary compromises an edge appliance, uses an inadvertent sudo configuration to escalate to root, and creates persistence via cron to tunnel traffic through DNS-over-HTTPS.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 2 of 3Research by Cisco Talos
UAT-10147: Host Elevation and Evasion
An adversary is executing automated staging scripts to deploy privilege escalation tools and blind security software on compromised web servers.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 1 of 3Research by Cisco Talos
Web Exploit and Telemetry Theft (UAT-10147)
The adversary exploits known web vulnerabilities in Zimbra, Telerik, or AjaxPro to achieve initial access and exfiltrates system identifiers to a Nacos configuration server via HTTP POST requests.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery