Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

XDR: Privilege Escalation

Premium room

Detect and investigate privilege escalation with Defender XDR.

medium

60 min

353

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

This room will discuss a privilege escalation technique from the perspective of a multi-stage incident in Microsoft Defender XDR.

  • Firstly, we will look at the privilege escalation concept.
  • Then, we will see a sample technique for it, namely  bypass.
  • Finally, we will investigate the multi-stage incident in Microsoft Defender XDR. While doing so, we will focus on the following parts of this incident, as each of them will help us to understand and build the attack narrative from a 360-degree view:
    • Attack story
    • Alerts
    • Assets
    • Investigations
    • Evidence and response

During the hands-on part, participants will also have the chance to explore and investigate similar alerts and incidents in the Microsoft Defender XDR lab environment. 

Answer the questions below

Let's get started!