Insider Threat Matrix™Insider Threat Matrix™
  • ID: PR024.002
  • Created: 22nd July 2026
  • Updated: 22nd July 2026
  • MITRE ATT&CK®: T1548T1548.003T1548.004T1548.005
  • Contributor: The ITM Team

Privilege Activation

The subject activates elevated permissions that are assigned to them or conditionally available through an established organizational or operating-system mechanism. This may include sudo, an elevation prompt, just-in-time access, privileged identity management, cloud role assumption, or an equivalent governed process.

 

The activation may itself be approved or unapproved. It should be recorded where entering the elevated context is materially relevant to an investigation, including where an approved mechanism is used outside its authorized purpose or before a later infringement.