What is privilege escalation?¶
Privilege escalation is obtaining greater authority than an account, process or user originally held. It explains the transition from an initial foothold to actions requiring local administrator, directory, cloud or application control.
Methods include exploiting a flaw, stealing privileged credentials, changing group membership, abusing excessive permissions, impersonating a process or activating a delegated role.
Prove the before-and-after state¶
Identify the starting security context, the higher privilege obtained, the mechanism and its time. Account and group changes, process tokens, role activations, administrative logs, commands and security alerts can document that transition.
Then connect the new authority to actions it enabled. The presence of exploit code is not proof that it succeeded, and escalation need not have occurred if the account already possessed sufficient privilege.
Follow escalation in stages¶
An offender may progress from ordinary user to local administrator and later to directory or cloud control. Preserve each step independently because different accounts, processes and evidence may be involved.
Activity under a valid privileged identity can look administratively normal. The account holder may not be the actor if credentials were compromised, the account was shared or automation used it. Report the privilege context before making a personal attribution.
Key takeaway
Demonstrate the original authority, the evidenced increase and the actions enabled, while keeping privileged account use separate from its owner's identity.