Techniques
Sample rules
Linux Usermod Root UID Set
- source: splunk
- technicques:
Description
The following analytic detects the use of usermod to set a user’s UID to 0. This functionally sets the user as a root user with full permissions. This approach can be used to bypass regular privilege escalation mechanisms, giving the attacker full control over the system while appearing as a regular user in most monitoring tools.
Detection logic
| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Processes
WHERE Processes.process_name="usermod"
AND (Processes.process IN ("* -u 0 *", "* -u 0") OR Processes.process="*--uid 0*")
BY Processes.action Processes.dest Processes.original_file_name
Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid
Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path
Processes.process Processes.process_current_directory Processes.process_exec
Processes.process_guid Processes.process_hash Processes.process_id
Processes.process_integrity_level Processes.process_name Processes.process_path
Processes.user Processes.user_id Processes.vendor_product
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_usermod_root_uid_set_filter`