Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What is misuse of privileged access?

Misuse of privileged access is unauthorised use of administrative or high-authority permissions. System capability does not give an administrator unlimited organisational authority.

Connect privilege to purpose

Preserve the privileged account and session, source device, approval or ticket, commands, target, time, result and later use. Compare the action with actual duties, procedures and normal management activity rather than judging it solely by power or unusual timing.

For emergency or break-glass access, retain activation, justification, approval and expiry. Exceptional access may be legitimate while use beyond the emergency purpose is not.

Trace upstream direction

Central tools and scripts may cause the target to record only a service account. Preserve the operator, job, instruction and approval chain, including where one administrator acted for another.

A privileged account may also be compromised. Keep the named holder, session controller and person directing automation separate until corroborated.

Key takeaway

Assess privileged actions against role, purpose, approval and outcome, tracing any management job to its controller before personal attribution.

Reference: CIM-234Cyber Incidents & Offender Methods