25 lines
702 B
YAML
25 lines
702 B
YAML
title: Add User To Root Group
|
|
id: qg3fcgdf3-rd54-9f48-4gh3-659a29b3db89
|
|
status: test
|
|
description: Detects add user to root group in linux using usermod
|
|
author: TuanLe (GTSC)
|
|
date: 2022/03/14
|
|
references:
|
|
- https://pberba.github.io/security/2021/11/23/linux-threat-hunting-for-persistence-account-creation-manipulation/
|
|
logsource:
|
|
product: linux
|
|
category: process_creation
|
|
detection:
|
|
selection:
|
|
Image|contains:
|
|
- 'usermod'
|
|
CommandLine|contains:
|
|
- '-aG root'
|
|
- '-aG sudoers'
|
|
condition: selection
|
|
falsepositives:
|
|
- Legitimate administration activities
|
|
level: medium
|
|
tags:
|
|
- attack.privilege_escalation
|