Privileged User Has Been Created

 Original Source: [Sigma source]
Title: Privileged User Has Been Created
Status: test
Description:Detects the addition of a new user to a privileged group such as "root" or "sudo"
References:
  -https://digital.nhs.uk/cyber-alerts/2018/cc-2825
  -https://linux.die.net/man/8/useradd
  -https://github.com/redcanaryco/atomic-red-team/blob/25acadc0b43a07125a8a5b599b28bbc1a91ffb06/atomics/T1136.001/T1136.001.md#atomic-test-5---create-a-new-user-in-linux-with-root-uid-and-gid
Author: Pawel Mazur
Date: 2022-12-21
modified:2025-01-21
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1136.001'
  • -'attack.t1098'
Logsource:
  • product: linux
  • definition: /var/log/secure on REHL systems or /var/log/auth.log on debian like Systems needs to be collected in order for this detection to work
Detection:
  selection_new_user:
    - 'new user'
  selection_uids_gids:
    - 'GID=0,'
    - 'UID=0,'
    - 'GID=10,'
    - 'GID=27,'
  condition:all of selection_*
Falsepositives:
  -Administrative activity
Level: high