Files
blue-team-tools/rules/linux/process_creation/proc_creation_lnx_usermod_command.yml
T
2022-03-15 17:36:10 +07:00

25 lines
702 B
YAML

title: Add User To Root Group
id: qg3fcgdf3-rd54-9f48-4gh3-659a29b3db89
status: test
description: Detects add user to root group in linux using usermod
author: TuanLe (GTSC)
date: 2022/03/14
references:
- https://pberba.github.io/security/2021/11/23/linux-threat-hunting-for-persistence-account-creation-manipulation/
logsource:
product: linux
category: process_creation
detection:
selection:
Image|contains:
- 'usermod'
CommandLine|contains:
- '-aG root'
- '-aG sudoers'
condition: selection
falsepositives:
- Legitimate administration activities
level: medium
tags:
- attack.privilege_escalation