Insider Threat Matrix™Insider Threat Matrix™
  • ID: PR024.003
  • Created: 22nd July 2026
  • Updated: 22nd July 2026
  • MITRE ATT&CK®: T1548T1548.001T1548.002T1548.003T1548.006
  • Contributor: The ITM Team

Elevation Control Circumvention

The subject bypasses, manipulates, or abuses a technical control intended to regulate elevated execution or access to protected capabilities. This may include abuse of set-user-ID or set-group-ID permissions, bypass of Windows User Account Control, manipulation of sudoers or cached sudo authorization, or alteration of platform consent and privacy controls.

 

This Sub-section concerns defeating or misusing the elevation control itself.