Privilege Escalation · Learn

Privilege escalation, in plain terms.

Privilege escalation is how an attacker turns a small foothold into full control of a machine: root on Linux, SYSTEM on Windows. This section explains, in plain language, the real paths, SUID and sudo and capabilities on Linux, impersonation and services and UAC on Windows, and how to find them before an attacker does.

TL;DR

Privilege escalation is the hinge between landing on a system and owning it. This section breaks the Linux and Windows paths into plain-language explainers with the real technical names a defender needs to recognise, each ending with how a penetration test surfaces that weakness in your own environment. Start with the foundations, then follow the Linux and Windows paths.

By John Dill, Red Team Lead, SecureLayer7Updated

Topics

Key terms explained

How to read this section

The pages are ordered the way escalation actually works.

  • Foundations first: what privilege escalation is, vertical and horizontal.
  • Linux: the path to root, SUID, sudo, capabilities, cron, PATH, kernel.
  • Windows: the path to SYSTEM, impersonation, services, install policy, UAC.
  • Enumeration: the tooling that finds these paths automatically.

Each explainer ends with how a penetration test confirms the weakness in your own systems.

References

  1. [1]MITRE ATT&CK: Privilege Escalation (TA0004)(MITRE)
  2. [2]NIST SP 800-115 Technical Guide to Security Testing(NIST)
  3. [3]Microsoft: Privilege Constants (Windows)(Microsoft)
Related terms

Scope an engagement

Find the privilege-escalation paths before an attacker does.

We run internal and host penetration tests that walk the real route from a low-privileged foothold to root or SYSTEM, then hand your team a report with reproducible evidence and a fix for every step. Free re-test included.

See all services30-min scoping call, fixed-price proposal in 48 hours.