Persistence Via Sudoers Files

 Original Source: [Sigma source]
Title: Persistence Via Sudoers Files
Status: test
Description:Detects the creation or modification of the main "/etc/sudoers" file or files within the "/etc/sudoers.d/" directory on Linux systems. Adversaries may alter sudoers configuration to execute commands with elevated privileges without supplying a password.
References:
  -https://www.sudo.ws/docs/man/sudoers.man/
  -https://github.com/h3xduck/TripleCross/blob/1f1c3e0958af8ad9f6ebe10ab442e75de33e91de/apps/deployer.sh
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-05
modified:2026-08-15
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1548.003'
Logsource:
  • product: linux
  • category: file_event
Detection:
  selection:
TargetFilename:'/etc/sudoers' TargetFilename|startswith:'/etc/sudoers.d/'   filter_main_dpkg:
    Image|endswith: '/usr/bin/dpkg'
    TargetFilename: '/etc/sudoers.d/README.dpkg-new'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Legitimate sudoers changes by administrators or configuration-management tools
Level: medium