mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update linux_sudoers_tmp_file_creation.yml
This commit is contained in:
@@ -7,7 +7,7 @@ type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This analytic is to looks for file creation of sudoers.tmp file cause
|
||||
by editing /etc/sudoers using visudo in linux platform. This technique may abuse
|
||||
by editing /etc/sudoers using visudo or editor in linux platform. This technique may abuse
|
||||
by adversaries, malware author and red teamers to gain elevated privilege to targeted
|
||||
or compromised host. /etc/sudoers file controls who can run what commands as what
|
||||
users on what machines and can also control special things such as whether you need
|
||||
|
||||
Reference in New Issue
Block a user