Back to Playbooks

Elevation of Privilege

Comprehensive incident response playbook for handling privilege escalation incidents where an attacker or insider gains unauthorized elevated access to systems, accounts, or resources. Covers detection of abnormal privilege changes, analysis of escalation techniques (token manipulation, SUID/SGID abuse, group policy exploitation, service account compromise), containment through access revocation, eradication via least-privilege enforcement and PAM hardening, and post-incident review based on the NIST Computer Security Incident Handling Guide (SP 800-61).

v1.0.0

This playbook follows the NIST Incident Response Framework with 7 phases and 14 total steps.

Response Phases

Click a phase to view its steps, or click a step to view its flowchart