Tag
Monitoring Unauthorized Modifications to Sudoers Configuration
1 rule 1 TTPAdversaries may attempt to escalate privileges on Unix-like systems by modifying the sudoers configuration file to grant unauthorized users or groups elevated permissions.
Detection of Web Server Access Log Deletion
1 rule 1 TTPAdversaries often delete web server access logs to destroy forensic evidence and evade detection after unauthorized activity, a behavior monitorable through file deletion events on common web server log paths.
Detecting Linux Defense Evasion via Executable Self-Deletion
1 rule 1 TTPAdversaries targeting Linux systems often execute payloads from ephemeral directories and immediately delete the binary to evade detection and hinder forensic investigation.
Suspicious Modification of Sensitive Linux Files
3 rules 1 TTPThis threat brief covers the detection of suspicious processes modifying sensitive files on Linux systems, potentially indicating malicious attempts to persist, escalate privileges, or disrupt system operations.