Access of Sudoers File Content

 Original Source: [Sigma source]
Title: Access of Sudoers File Content
Status: test
Description:Detects the execution of a text-based file access or inspection utilities to read the content of /etc/sudoers in order to potentially list all users that have sudo rights.
References:
  -https://github.com/sleventyeleven/linuxprivchecker/
Author: Florian Roth (Nextron Systems)
Date: 2022-06-20
modified:2025-06-04
Tags:
  • -'attack.reconnaissance'
  • -'attack.t1592.004'
Logsource:
  • category: process_creation
  • product: linux
Detection:
  selection:
    Image|endswith:
      -'/cat'
      -'/ed'
      -'/egrep'
      -'/emacs'
      -'/fgrep'
      -'/grep'
      -'/head'
      -'/less'
      -'/more'
      -'/nano'
      -'/tail'

    CommandLine|contains: ' /etc/sudoers'
  condition:selection
Falsepositives:
  -Legitimate administration activities
Level: medium