Tailscale: User role elevated to admin or owner

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies when a user's tailnet role changes from a lower-privilege role to admin, network-admin, or owner between consecutive snapshots. Privilege escalation is a high-value attacker objective and warrants prompt review.

Attribute Value
Type Analytic Rule
Solution Tailscale (CCF)
ID d3c4e5f6-3456-7890-12ab-cdef12345003
Severity High
Status Available
Kind Scheduled
Tactics PrivilegeEscalation, Persistence
Techniques T1078, T1098
Required Connectors TailscaleCCF
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Tailscale_Users_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Tailscale (CCF)