T1548 - Abuse Elevation Control - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 7, 2026
Last Seen
January 7, 2026

T1548 - Abuse Elevation Control refers to techniques where adversaries exploit operating system elevation controls to obtain higher privileges, enabling persistence, defense evasion, and broader access within a network.

Overview

T1548 - Abuse Elevation Control refers to techniques where adversaries exploit operating system elevation controls to obtain higher privileges, enabling persistence, defense evasion, and broader access within a network. Key methods include bypassing User Account Control (UAC), token impersonation, and abusing legitimate privileged processes or signed binaries. The recent campaign described as a sophisticated, multi-stage attack against manufacturing and government sectors demonstrates the technique's critical role in enabling elevated access for subsequent actions.

Related Threat Clusters

Recent Intelligence Reports

  • Sophisticated multi-stage attack targets manufacturing, governments — Scworld · January 7, 2026

CVSS v3.1 Breakdown