Privilege escalation is the process attackers use to gain higher-level access on a system after an initial compromise. This coverage explains the techniques adversaries employ to move from limited access to full control over a target resource.
Privilege Escalation
Many times when we have access to a server, it's not necessarily the right access to carry out an attack. There are many times when an adversary gets into a network and then needs to escalate their privilege.
When a hacker gains access to a system, many times they don't have the right access to that system. There are a lot of things that are locked down, for instance, on a web server. So if they gain access to that web server, then perhaps what they need to do is escalate the privileges. There are mechanisms and ways that they can get onto that server to exploit different vulnerabilities on that server, to escalate the privilege and bring it to the next level.
In our example, as a web application, one thing that they might do is want to log into maybe some sort of Linux box, a Linux web server, as root, and then they can just do anything that they want on that box.
So, privilege escalation, pretty straightforward: when the adversary is trying to escalate their privilege on a server or some sort of resource.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →