Skip to content

Hide Navigation Hide TOC

Tool Misuse — Privilege Escalation via Social Engineering Agent to Grant Access - ATR-2026-00720 (12f67cd7-81cd-52f4-98a5-0210d99db1e7)

Detects requests where a user socially engineers an agent with access control tools to grant unauthorized access: inviting users to Slack workspaces and channels, granting delivery personnel house access for plausible pretexts, adding users to calendars or CRM systems with excessive permissions. The attacker provides a plausible social justification to bypass normal access control review. Source: tool-misuse-privilege-escalation (ToolEmu corpus).

Cluster A Galaxy A Cluster B Galaxy B Level
Tool Misuse — Privilege Escalation via Social Engineering Agent to Grant Access - ATR-2026-00720 (12f67cd7-81cd-52f4-98a5-0210d99db1e7) Agent Threat Rules LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 1