T1548.003 Sudo and Sudo Caching
Sub-technique of T1548 Abuse Elevation Control Mechanism
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges. Within Linux and MacOS systems, sudo (sometimes referred to as "superuser do") allows users to perform commands from terminals with elevated privileges and to control who can perform these commands on the…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Sudo Privilege Escalation CVE-2019-14287 - Builtincriticaltest · linux
- Sudo Privilege Escalation CVE-2019-14287hightest · linux
- Persistence Via Sudoers.d Filesmediumtest · linux
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.