T1626 Abuse Elevation Control Mechanism
Adversaries may circumvent mechanisms designed to control elevated privileges to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can gain on a machine. Authorization has to be granted to specific users in order to perform tasks that are designated as higher risk. An adversary can use several methods to take advantage of built-in control mechanisms in order to escalate privileges on a system.
| Item | Value |
|---|---|
| ID | T1626 |
| Sub-techniques | T1626.001 |
| Tactics | TA0029 |
| Platforms | Android |
| Version | 1.1 |
| Created | 01 April 2022 |
| Last Modified | 24 October 2025 |
Mitigations
| ID | Mitigation | Description |
|---|---|---|
| M1013 | Application Developer Guidance | Applications very rarely require administrator permission. Developers should be cautioned against using this higher degree of access to avoid being flagged as a potentially malicious application. |