THREATOPS
THREAT OPSThreat News › Linux Detection Engineering - Local Privilege Escalation

Linux Detection Engineering - Local Privilege Escalation

medelastic_securityPublished 2026-09-11

<p><a href="https://attack.mitre.org/tactics/TA0004/">Local privilege escalation</a> (LPE) is the step that turns a foothold into full control of a host. An attacker who lands as an unprivileged user rarely stops there. They want root, and Linux keeps offering new ways to get it.</p><p>In this edition of our "Linux Detection Engineering" series, we’ll cover:</p><ul><li><p>The default flow that a L

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.elastic.co/security-labs/threat-command/linux-privilege-escalation-detection-framework