Log sources › auditd:CONFIG_CHANGE
auditd:CONFIG_CHANGE
Inverted view: what can be detected if this is the log you have. Linux
6
channels
6
analytics
6
techniques
2
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
/etc/fstab, /etc/systemd/* |
DC0040 File Deletion | AN0934 | 1 |
/var/log/audit/audit.log |
DC0012 Scheduled Job Modification | AN0325 | 1 |
chmod or chown of hook files indicating privilege escalation or execution permission change |
DC0059 File Metadata | AN0713 | 1 |
creation or modification of systemd services |
DC0060 Service Creation | AN0200 | 1 |
delete: Modification of systemd unit files or config for security agents |
DC0041 Service Metadata | AN1370 | 1 |
udev rule reload or trigger command executed |
DC0064 Command Execution | AN1056 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1036.004 Masquerade Task or Service | stealth | 3 | 0 |
| T1490 Inhibit System Recovery | impact | 27 | 2 |
| T1546.017 Udev Rules | persistence, privilege escalation | 0 | 0 |
| T1546.018 Python Startup Hooks | persistence, privilege escalation | 0 | 0 |
| T1569.003 Systemctl | execution | 0 | 0 |
| T1685 Disable or Modify Tools | defense impairment | 164 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2023-36884 | Microsoft Windows | T1490 | Stale |
| CVE-2025-21391 | Microsoft Windows | T1490 | Mapped |