Privilege escalation

Escalation is frequently not an exploit. It is finding a credential somebody left lying around.

A password in a script, a token in a config file, an over-permissioned service account, a group membership nobody reviewed. In modern environments the path from ordinary user to administrator is usually a chain of small misconfigurations rather than a technical vulnerability, which is why hardening beats patching for this particular step.

Checked against the primary source.

More on Threat actors & ATT&CK