Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingAccess ManagementCybersecurity News

Protecting against Windows privilege escalation tactics and techniques

By Joseph Carson
cyber-protection-freepik1170x658v47.jpg

Image via Freepik

July 15, 2022

Privilege escalation remains one of the top techniques utilized by attackers to discover and exfiltrate sensitive and valuable data from organizations. Defined, privilege escalation is the process of increasing privileges from initial access, typically a standard user or application account, all the way up to extending privileges to administrator, root, or even full system access.


When targeting privilege accounts, cybercriminals continually utilize proven techniques and follow similar courses of action to identify and exploit any weak credentials, misconfigurations or overprivileged users which exist within a particular organizational system or network. Domain admin and service accounts, local administrator accounts and privileged data user accounts are just some of the most common privileged accounts that cybercriminals frequently target. However, it should never be assumed that attackers only target accounts where access and privileges are plentiful. Cybercriminals are ultimately looking for ideal situations where privileged accounts are left unmanaged and unmonitored.


When evaluating an organization’s environment, attackers are looking for security vulnerabilities that allow for privilege escalation exploits, including:

 

  • Passwords: Organizations often leave credential details for privileged users in a text file on a desktop, browser, or configuration file. Attackers can quickly search for stored passwords using common techniques such as searching the registry using the query: reg query HKLM /f password /t REG_SZ /s or finding a text file on the desktop labeled something like “passwords,” or “important stuff.”
  • Overprivileged Users: Attackers are also searching for users who have been allocated more privileges than required for their job responsibilities with access to systems and data they do not need. For example, standard business users may have Local Administrator rights on their personal workstations. Attackers can leverage these Local Administrator rights to escalate privileges up to Full Domain using tools. 
  • Unprotected service permissions: These are situations where a particular service is running under system privileges, but a user has the permissions and ability to change the executable binPath, which could as a result create a reverse shell.
  • Weak registry permissions: Like insecure service permissions, if an attacker can modify the registry configuration of a service, they can also change the path in the service configuration. This could again create a reverse shell or elevate privileges on the system.


These are only some of the common attack strategies used to escalate privileges as cybercriminals continue to develop new ways to discreetly execute their attack.


Cybersecurity Best Practices

On a more positive note, there are host of different defense mechanisms that can be implemented to protect against the rising sophistication attackers exhibit while escalating privileges. Firstly, it must never be assumed that an organization can successfully ‘prevent’ an attack. This is a dangerous assumption made by many organizations that leads to a false sense of security. Instead, organizations should focus on reducing risk, making it more challenging for attackers to be successful and increasing visibility to stop the progression of exploits before they can elevate privileges and stop them in their tracks before any serious damage is done.


There are several ways this can be achieved:

  1. Multi-Factor Authentication: Passwords should never be the only security control for accessing critical systems, applications, and privileges. By implementing multi-factor authentication controls, it adds an extra layer of protection, should an attacker be able to compromise a password. MFA should be required not only at system log-in, but also at the point of horizontal and vertical privilege elevation. 
  2. Update and Patch Systems: While this practice is by no means completely effective, regularly updating and patching critical systems will make an attacker’s objective of executing a privileged attack and escalation more difficult.
  3. Utilize Privileged Access Management: Privileged Access Management can help organization store their passwords by moving them into secure vaults so that they are not easily found by attackers during the enumeration phase. Privileged Access Management will help avoid passwords being left on the desktop in clear text, hidden in configuration files, or stored in insecure browsers. It will also ensure that all services have a provisioned account with the correct security controls, including complex passwords, rotated frequently.
  4. Least Privilege Approach: All organizations should adopt a least privilege approach where users are only allocated the privileges needed to complete the task or action they are assigned to do. This reduces the possibility of exposing several of the privilege escalation paths, such as insecure services, registry, and directory paths.
  5. Control Applications: Organizations should focus on limiting running applications and scripts that can be used to enumerate or exploit privileges. Implementing approval or ‘allow’ lists will help control which applications and scripts can execute, while deny lists will ensure malicious applications and scripts are blocked or require additional auditing.
  6. Audit Privilege Access Usage: Privilege usage should be constantly monitored for any suspicious behavior or activity. Alerts that immediately notify security and IT teams of any deviation from normal activity must be implemented. Should a privilege escalation exploit occur, you’ll be able to conduct incident response and identify the root cause of the attack to prevent it from happening again.

This article originally ran in Today’s Cybersecurity Leader, a monthly cybersecurity-focused eNewsletter for security end users, brought to you by Security magazine. Subscribe here.

KEYWORDS: cyber security incident response multi-factor authentication risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Joseph Carson is a cybersecurity professional with more than 25 years' experience in enterprise security and infrastructure. Currently, Carson is the Chief Security Scientist & Advisory CISO at Thycotic. He is an active member of the cybersecurity community and a Certified Information Systems Security Professional (CISSP). Carson is a cybersecurity adviser to several governments, critical infrastructure organizations, and financial and transportation industries, and speaks at conferences globally.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Soccer stadium

How the Current Iran-US Conflict May Impact World Cup Security

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Neighborhood

Residential AI Data Centers: Security, Privacy, and Governance Concerns

SEC 2026 Benchmark Banner

Events

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

LIVE: July 8, 2026 at 2 pm EDT In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • network security cyber

    Enterprise SIEMs unprepared for 84% of MITRE ATT&CK tactics and techniques

    See More
  • Ukraine

    Protecting against cyber threats during the Russia-Ukraine conflict

    See More
  • Protecting Against the Thieves Within: How to Implement an Effective Fraud Prevention Program

    See More

Related Products

See More Products
  • 1119490936.jpg

    Solving Cyber Risk: Protecting Your Company and Society

  • The Database Hacker's Handboo

  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing