Sub-technique of T1548 Abuse Elevation Control Mechanism.View on attack.mitre.org
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges.
Within Linux and MacOS systems, sudo (sometimes referred to as "superuser do") allows users to perform commands from terminals with elevated privileges and to control who can perform these commands on the system. The sudo command "allows a system administrator to delegate authority to give certain users (or groups of users) the ability to run some (or all) commands as root or another user while providing an audit trail of the commands and their arguments." Since sudo was made for the system administrator, it has some useful configuration features such as a timestamp_timeout, which is the amount of time in minutes between instances of sudo before it will re-prompt for a password. This is because sudo has the ability to cache credentials for a period of time. Sudo creates (or touches) a file at /var/db/sudo with a timestamp of when sudo was last run to determine this timeout. Additionally, there is a tty_tickets variable that treats each new tty (terminal session) in isolation. This means that, for example, the sudo timeout of one tty will not affect another tty (you will have to type the password again).
The sudoers file, /etc/sudoers, describes which users can run which commands and from which terminals. This also describes which commands users can run as other users or groups. This provides the principle of least privilege such that users are running in their lowest possible permissions for most of the time and only elevate to other users or permissions as needed, typically by prompting for a password. However, the sudoers file can also specify when to not prompt users for passwords with a line like user1 ALL=(ALL) NOPASSWD: ALL. Elevated privileges are required to edit this file though.
Adversaries can also abuse poor configurations of these mechanisms to escalate privileges without needing the user's password. For example, /var/db/sudo's timestamp can be monitored to see if it falls within the timestamp_timeout range. If it does, then malware can execute sudo commands without needing to supply the user's password. Additional, if tty_tickets is disabled, adversaries can do this from any tty for that user.
In the wild, malware has disabled tty_tickets to potentially make scripting easier by issuing echo \'Defaults !tty_tickets\' >> /etc/sudoers. In order for this change to be reflected, the malware also issued killall Terminal. As of macOS Sierra, the sudoers file has tty_tickets enabled by default.
Rules on DetectionCode tagged with T1548.003.
| Rule | Level | Log source |
|---|---|---|
| Sudo Privilege Escalation CVE-2019-14287 - Builtin | critical | linux / NULL |
| Sudo Privilege Escalation CVE-2019-14287 | high | linux / process_creation |
| Persistence Via Sudoers Files | medium | linux / file_event |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Linux APT Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1, Cisco Isovalent Process Exec |
| Linux apt-get Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1, Cisco Isovalent Process Exec |
| Linux Auditd Doas Conf File Creation | TTP | NULL | Linux Auditd Path, Linux Auditd Cwd |
| Linux Auditd Doas Tool Execution | Anomaly | NULL | Linux Auditd Syscall |
| Linux Auditd Nopasswd Entry In Sudoers File | Anomaly | NULL | Linux Auditd Proctitle |
| Linux Auditd Possible Access To Sudoers File | Anomaly | NULL | Linux Auditd Path, Linux Auditd Cwd |
| Linux Auditd Sudo Or Su Execution | Anomaly | NULL | Linux Auditd Proctitle |
| Linux AWK Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Busybox Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux c89 Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux c99 Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Composer Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Cpulimit Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Csvtool Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Doas Conf File Creation | Anomaly | NULL | Sysmon for Linux EventID 11 |
| Linux Doas Tool Execution | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Docker Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Emacs Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Find Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux GDB Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Gem Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux GNU Awk Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Make Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux MySQL Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Node Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux NOPASSWD Entry In Sudoers File | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Octave Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux OpenVPN Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux PHP Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Possible Access To Sudoers File | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Puppet Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux RPM Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Ruby Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Sqlite3 Privilege Escalation | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Sudo OR Su Execution | Hunting | NULL | Sysmon for Linux EventID 1 |
| Linux Sudoers Tmp File Creation | Anomaly | NULL | Sysmon for Linux EventID 11 |
| Linux Visudo Utility Execution | Anomaly | NULL | Sysmon for Linux EventID 1 |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareCanisterWorm | CanisterWorm has checked if the current user is root. If it is, CanisterWorm will wipe the system using `rm –rf / --no-preserve-root`. If it is not, CanisterWorm will try passwordless sudo and will run the same command. |
| MalwareCobalt Strike | Cobalt Strike can use |
| MalwareDok | Dok adds |
| MalwareProton | Proton modifies the tty_tickets line in the sudoers file. |
| MalwareShai-Hulud | Shai-Hulud has attempted to gain root access by leveraging `sudo` and `/etc/sudoers.d`. |
| MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can use `sudo` for code execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.