{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/security-events/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["low"],"_cs_tags":["macos","privilege-escalation","credential-access","security-events"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis threat brief focuses on detecting unauthorized attempts to gain administrative privileges on macOS systems. Attackers who have obtained initial access through a low-privileged account often attempt to escalate privileges by brute-forcing or guessing administrator credentials via the sudo mechanism. macOS logs failed sudo attempts to the unified log, recording information such as the invoking user, the target user, the number of failures, and the requested command. By monitoring the Authentication data stream (logs-macos.authentication-*) provided by the macOS Security Events integration, detection engineers can identify abnormal volumes of failed sudo attempts. A threshold of 10 or more failed attempts within a 9-minute window is a common indicator of automated or manual credential guessing, warranting investigation into the invoking user account and the originating session.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this activity grants an attacker unauthorized administrative access to the affected macOS host. This enables further malicious actions including credential dumping, persistence establishment, reconnaissance, or malware execution. Targeted systems are typically those exposed to remote access or those with multiple users sharing a single machine.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided ESQL detection rule to the SIEM environment to monitor for excessive sudo failures.\u003c/li\u003e\n\u003cli\u003eReview authentication logs (logs-macos.authentication-*) when the detection rule triggers to differentiate between malicious intent and legitimate user error.\u003c/li\u003e\n\u003cli\u003eInvestigate the originating TTY and session type (e.g., local versus SSH) to determine the attacker's point of entry.\u003c/li\u003e\n\u003cli\u003eAudit administrative group memberships and restrict sudo access to the minimum number of users required.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T10:10:12Z","date_published":"2026-09-28T10:10:12Z","id":"https://feed.craftedsignal.io/briefs/2026-09-macos-sudo-brute/","summary":"Detection of potential privilege escalation or credential access attempts via repeated sudo authentication failures on macOS hosts.","title":"Excessive Sudo Authentication Failures on macOS","url":"https://feed.craftedsignal.io/briefs/2026-09-macos-sudo-brute/"}],"language":"en","title":"CraftedSignal Threat Feed - Security-Events","version":"https://jsonfeed.org/version/1.1"}