Attack Lifecycle · Stage 5 of 7
Stage 5: Privilege Escalation
May 2026 · 8 min read · MITRE ATT&CK · Admin Access · Root Compromise · UAC Bypass
Stage 5 of the cyberattack lifecycle: Privilege Escalation. The attacker elevates their access from a standard user to administrator or root — gaining the power to control critical systems and disable security controls.
Attacker Goal
Obtain higher-level permissions to control critical systems, disable security tools, and prepare for the final attack stages.
MITRE ATT&CK Techniques
T1068T1055T1134T1548T1078.003T1484
Stage Description
The attacker elevates their access from a standard user to administrator or root — gaining the power to control critical systems and disable security controls.
Common Entry Vectors
- Exploiting software vulnerabilities to gain elevated privileges
- Token manipulation to impersonate privileged accounts
- Abusing misconfigured sudo rules in Linux systems
- UAC bypass techniques on Windows systems
- Exploiting group policy and Active Directory misconfigurations
Typical Attacker Actions
- Exploits local vulnerabilities to gain administrator rights
- Manipulates access tokens to impersonate privileged users
- Abuses service accounts with excessive permissions
- Modifies group policies to expand access
- Disables security tools and logging after gaining admin access
✓ Purim NetGo Detection & Response
- Canary admin accounts that alert when accessed or modified
- Honeypot domain administrator credentials
- Fake privileged service accounts that trigger on use
- Alerts fire the moment anyone attempts to use canary admin credentials
- Full intelligence on the escalation attempt including source device
What Purim NetGo Delivers at This Stage
- Escalation Detection — catch privilege abuse immediately
- Admin Account Monitoring — protect your highest-value credentials
- Early Warning — detect before admin access is weaponized
- Complete Intelligence — know exactly who, what, and from where
- Critical Asset Protection — guard your most sensitive accounts
See It In Action
Get a real simulated attack alert sent to your inbox — experience deception security firsthand.
Launch Free Test Drive