LoFP LoFP / creation of legitimate files in sudoers.d folder part of administrator work

Techniques

Sample rules

Persistence Via Sudoers Files

Description

Detects creation of sudoers file or files in “sudoers.d” directory which can be used a potential method to persiste privileges for a specific user.

Detection logic

condition: selection
selection:
  TargetFilename|startswith: /etc/sudoers.d/