Linux Keylogging with Pam.d

 Original Source: [Sigma source]
Title: Linux Keylogging with Pam.d
Status: test
Description:Detect attempt to enable auditing of TTY input
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1056.001/T1056.001.md
  -https://linux.die.net/man/8/pam_tty_audit
  -https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security_guide/sec-configuring_pam_for_auditing
  -https://access.redhat.com/articles/4409591#audit-record-types-2
Author: Pawel Mazur
Date: 2021-05-24
modified:2022-12-18
Tags:
  • -'attack.collection'
  • -'attack.credential-access'
  • -'attack.t1003'
  • -'attack.t1056.001'
Logsource:
  • product: linux
  • service: auditd
Detection:
  selection_path_events:
    type: 'PATH'
    name:
      -'/etc/pam.d/system-auth'
      -'/etc/pam.d/password-auth'

  selection_tty_events:
    type:
      -'TTY'
      -'USER_TTY'

  condition:1 of selection_*
Falsepositives:
  -Administrative work
Level: high