Skip to content
Threat Feed
low advisory

Excessive Sudo Authentication Failures on macOS

Detection of potential privilege escalation or credential access attempts via repeated sudo authentication failures on macOS hosts.

This threat brief focuses on detecting unauthorized attempts to gain administrative privileges on macOS systems. Attackers who have obtained initial access through a low-privileged account often attempt to escalate privileges by brute-forcing or guessing administrator credentials via the sudo mechanism. macOS logs failed sudo attempts to the unified log, recording information such as the invoking user, the target user, the number of failures, and the requested command. By monitoring the Authentication data stream (logs-macos.authentication-*) provided by the macOS Security Events integration, detection engineers can identify abnormal volumes of failed sudo attempts. A threshold of 10 or more failed attempts within a 9-minute window is a common indicator of automated or manual credential guessing, warranting investigation into the invoking user account and the originating session.

Impact

Successful exploitation of this activity grants an attacker unauthorized administrative access to the affected macOS host. This enables further malicious actions including credential dumping, persistence establishment, reconnaissance, or malware execution. Targeted systems are typically those exposed to remote access or those with multiple users sharing a single machine.

Recommendation

  • Deploy the provided ESQL detection rule to the SIEM environment to monitor for excessive sudo failures.
  • Review authentication logs (logs-macos.authentication-*) when the detection rule triggers to differentiate between malicious intent and legitimate user error.
  • Investigate the originating TTY and session type (e.g., local versus SSH) to determine the attacker's point of entry.
  • Audit administrative group memberships and restrict sudo access to the minimum number of users required.

Immediate actions

Deploy the ESQL detection rule for excessive sudo failures to the SIEM.

Detection Engineering 48h

Threat Hunt

Search authentication logs for accounts with high volumes of sudo failures not followed by a successful authentication.

T1110.001 medium high confidence hunt now

Data: logs-macos.authentication-*

Mitigations

Review and restrict sudoers file configuration.

medium_term IT Operations

T1548.003