MITRE ATT&CK Tactic
Privilege Escalation
4 queries tagged with this tactic.
View on MITRE ATT&CK →
-
Analytics Rules
Detect Autogen Studio Agent Tool Execution Anomaly
AutoGen Studio-hosted AI agent taking code-execution or sensitive-tool actions outside its baseline set — the 'AutoJack' agent-abuse shape.
-
Hunting
Hunt First Time Admin Operation User Baseline
Baselines identities that have ever executed admin operations, then alerts when an account outside that set succeeds — 'the admin who has never administered.'
-
Hunting
Hunt Suspicious User Consented Oauth App Grants
'The backdoor you approved yourself' — OAuth application consents granting broad Graph permissions to unfamiliar apps. Focuses on CONSENT events, not the logins that follow.
-
Identity
Whos Activating Roles Via PIM
PIM role activations from `AuditLogs` — useful for tracking privileged-role usage.