{"id":"T1548.003","name":"Sudo and Sudo Caching","url":"https://attack.mitre.org/techniques/T1548/003","tactics":["privilege-escalation"],"platforms":["Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0052","stix_id":"x-mitre-detection-strategy--31f41970-898c-4c64-b018-e03eabb81916","name":"Behavioral Detection Strategy for Abuse of Sudo and Sudo Caching","url":"https://attack.mitre.org/detectionstrategies/DET0052","analytics":[{"id":"AN0142","stix_id":"x-mitre-analytic--0994985d-1d45-478e-9f1c-f407eb297007","name":"Analytic 0142","description":"Correlate command executions involving 'sudo' with elevated effective user ID (euid=0), especially when tty_tickets is disabled or timestamp_timeout is actively abused.","url":"https://attack.mitre.org/detectionstrategies/DET0052#AN0142","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve call for sudo where euid != uid","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve call for modification of /etc/sudoers or writing to /var/db/sudo","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"timestamp_timeout_threshold","description":"Tune the valid sudo session duration to reduce false positives"},{"field":"command_allowlist","description":"Filter benign sudo usage (e.g., approved admin scripts)"}],"live":true,"detection_strategies":["DET0052"],"techniques":["T1548.003"]},{"id":"AN0143","stix_id":"x-mitre-analytic--8825b589-3a6a-483a-9fc0-a4d00b1183ab","name":"Analytic 0143","description":"Detect sudo activity with NOPASSWD in /etc/sudoers or disabling tty_tickets, followed by immediate privileged commands (e.g., echo 'Defaults !tty_tickets' >> /etc/sudoers).","url":"https://attack.mitre.org/detectionstrategies/DET0052#AN0143","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"exec or sudo usage with NOPASSWD context or echo modifying sudoers","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Terminal process killed (killall Terminal) immediately after sudoers modification","data_component":"DC0033","data_component_name":"Process Termination","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"admin_user_context","description":"Define allowed users who may modify sudoers without investigation"},{"field":"terminal_restart_window","description":"Time window after sudoers file change to monitor for Terminal restarts"}],"live":true,"detection_strategies":["DET0052"],"techniques":["T1548.003"]}],"live":true,"version":"1.0","techniques":["T1548.003"]}],"sigma_rules":[{"id":"7fcc54cb-f27d-4684-84b7-436af096f858","title":"Sudo Privilege Escalation CVE-2019-14287 - Builtin","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2019-10-15","modified":"2022-11-26","description":"Detects users trying to exploit sudo vulnerability reported in CVE-2019-14287","references":["https://www.openwall.com/lists/oss-security/2019/10/14/1","https://access.redhat.com/security/cve/cve-2019-14287","https://twitter.com/matthieugarin/status/1183970598210412546"],"logsource":{"product":"linux","service":"sudo"},"tags":["attack.privilege-escalation","attack.t1068","attack.t1548.003","cve.2019-14287","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Exploits/CVE-2019-14287/lnx_sudo_exploit_cve_2019_14287.yml","techniques":["T1068","T1548.003"],"cves":["CVE-2019-14287"]},{"id":"ddb26b76-4447-4807-871f-1b035b2bfa5d","title":"Persistence Via Sudoers.d Files","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-07-05","modified":"2026-03-18","description":"Detects the creation or modification of files within the \"sudoers.d\" directory on Linux systems.\nSuch activity may indicate an attempt to establish or maintain privilege escalation by granting specific users elevated permissions.\nUnauthorized changes to sudoers files are a common technique used by attackers to persist administrative access.\n","references":["https://github.com/h3xduck/TripleCross/blob/1f1c3e0958af8ad9f6ebe10ab442e75de33e91de/apps/deployer.sh"],"logsource":{"product":"linux","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1548.003"],"path":"rules/linux/file_event/file_event_lnx_persistence_sudoers_files.yml","techniques":["T1548.003"],"cves":[]},{"id":"f74107df-b6c6-4e80-bf00-4170b658162b","title":"Sudo Privilege Escalation CVE-2019-14287","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-10-15","modified":"2022-10-05","description":"Detects users trying to exploit sudo vulnerability reported in CVE-2019-14287","references":["https://www.openwall.com/lists/oss-security/2019/10/14/1","https://access.redhat.com/security/cve/cve-2019-14287","https://twitter.com/matthieugarin/status/1183970598210412546"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1068","attack.t1548.003","cve.2019-14287","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Exploits/CVE-2019-14287/proc_creation_lnx_exploit_cve_2019_14287.yml","techniques":["T1068","T1548.003"],"cves":["CVE-2019-14287"]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}