This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Privileged User Has Been Created
Original Source:
[Sigma source]
Title:
Privileged User Has Been Created
Status:
test
Description:
Detects the addition of a new user to a privileged group such as "root" or "sudo"
References:
-https://digital.nhs.uk/cyber-alerts/2018/cc-2825
-https://linux.die.net/man/8/useradd
-https://github.com/redcanaryco/atomic-red-team/blob/25acadc0b43a07125a8a5b599b28bbc1a91ffb06/atomics/T1136.001/T1136.001.md#atomic-test-5---create-a-new-user-in-linux-with-root-uid-and-gid
Author:
Pawel Mazur
Date:
2022-12-21
modified:
2025-01-21
Tags:
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.t1136.001'
-'attack.t1098'
Logsource:
product: linux
definition: /var/log/secure on REHL systems or /var/log/auth.log on debian like Systems needs to be collected in order for this detection to work
Detection:
selection_new_user:
- 'new user'
selection_uids_gids:
- 'GID=0,'
- 'UID=0,'
- 'GID=10,'
- 'GID=27,'
condition
:
all of selection_*
Falsepositives:
-Administrative activity
Level:
high