LoFP LoFP / legitimate sudoers changes by administrators or configuration-management tools

Techniques

Sample rules

Persistence Via Sudoers Files

Description

Detects the creation or modification of the main “/etc/sudoers” file or files within the “/etc/sudoers.d/” directory on Linux systems. Adversaries may alter sudoers configuration to execute commands with elevated privileges without supplying a password.

Detection logic

condition: selection and not 1 of filter_main_*
filter_main_dpkg:
  Image|endswith: /usr/bin/dpkg
  TargetFilename: /etc/sudoers.d/README.dpkg-new
selection:
- TargetFilename: /etc/sudoers
- TargetFilename|startswith: /etc/sudoers.d/