Techniques
Sample rules
Persistence Via Sudoers Files
- source: sigma
- technicques:
- t1548
- t1548.003
Description
Detects the creation or modification of the main “/etc/sudoers” file or files within the “/etc/sudoers.d/” directory on Linux systems. Adversaries may alter sudoers configuration to execute commands with elevated privileges without supplying a password.
Detection logic
condition: selection and not 1 of filter_main_*
filter_main_dpkg:
Image|endswith: /usr/bin/dpkg
TargetFilename: /etc/sudoers.d/README.dpkg-new
selection:
- TargetFilename: /etc/sudoers
- TargetFilename|startswith: /etc/sudoers.d/