LoFP LoFP / setting a user's uid to 0 is extremely rare in legitimate administration — there is almost no valid operational reason to create a second root-equivalent account this way. false positives are expected to be very low. verify any alert against change management records before dismissing.

Techniques

Sample rules

Linux Usermod Root UID Set

Description

The following analytic detects the use of usermod to set a user’s UID to 0. This functionally sets the user as a root user with full permissions. This approach can be used to bypass regular privilege escalation mechanisms, giving the attacker full control over the system while appearing as a regular user in most monitoring tools.

Detection logic


| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Processes
WHERE Processes.process_name="usermod"
  AND (Processes.process IN ("* -u 0 *", "* -u 0") OR Processes.process="*--uid 0*")
BY Processes.action Processes.dest Processes.original_file_name
   Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid
   Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path
   Processes.process Processes.process_current_directory Processes.process_exec
   Processes.process_guid Processes.process_hash Processes.process_id
   Processes.process_integrity_level Processes.process_name Processes.process_path
   Processes.user Processes.user_id Processes.vendor_product

| `drop_dm_object_name(Processes)`

| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `linux_usermod_root_uid_set_filter`