EXPLORE
← Back to Explore
T1548.003

Sudo and Sudo Caching

Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges. Within Linux and MacOS systems, sudo (sometimes referred to as "superuser do") allows users to perform commands from terminals with elevated privileges and to control who can perform these commands on the system. The <code>sudo</code> command "allows a system administrator to delegate authority to give certa...

LinuxmacOS
49
Detections
2
Sources
0
Threat Actors

BY SOURCE

35splunk_escu14elastic

PROCEDURES (14)

General Monitoring19 detections

Auto-extracted: 19 detections for general monitoring

Persist7 detections

Auto-extracted: 7 detections for persist

Process Creation Monitoring4 detections

Auto-extracted: 4 detections for process creation monitoring

Persist3 detections

Auto-extracted: 3 detections for persist

Persist2 detections

Auto-extracted: 2 detections for persist

Script Execution Monitoring2 detections

Auto-extracted: 2 detections for script execution monitoring

Suspicious2 detections

Auto-extracted: 2 detections for suspicious

Parent Process2 detections

Auto-extracted: 2 detections for parent process

Container2 detections

Auto-extracted: 2 detections for container

File Monitoring2 detections

Auto-extracted: 2 detections for file monitoring

Service1 detections

Auto-extracted: 1 detections for service

Exfiltrat1 detections

Auto-extracted: 1 detections for exfiltrat

Service1 detections

Auto-extracted: 1 detections for service

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

DETECTIONS (49)

Deprecated - Sudo Heap-Based Buffer Overflow Attempt
elastichigh
Linux APT Privilege Escalation
splunk_escu
Linux Auditd Doas Conf File Creation
splunk_escu
Linux Auditd Doas Tool Execution
splunk_escu
Linux Auditd Nopasswd Entry In Sudoers File
splunk_escu
Linux Auditd Possible Access To Sudoers File
splunk_escu
Linux Auditd Sudo Or Su Execution
splunk_escu
Linux AWK Privilege Escalation
splunk_escu
Linux Busybox Privilege Escalation
splunk_escu
Linux c89 Privilege Escalation
splunk_escu
Linux c99 Privilege Escalation
splunk_escu
Linux Composer Privilege Escalation
splunk_escu
Linux Cpulimit Privilege Escalation
splunk_escu
Linux Csvtool Privilege Escalation
splunk_escu
Linux Doas Conf File Creation
splunk_escu
Linux Doas Tool Execution
splunk_escu
Linux Emacs Privilege Escalation
splunk_escu
Linux Find Privilege Escalation
splunk_escu
Linux GDB Privilege Escalation
splunk_escu
Linux Gem Privilege Escalation
splunk_escu
Linux GNU Awk Privilege Escalation
splunk_escu
Linux Make Privilege Escalation
splunk_escu
Linux MySQL Privilege Escalation
splunk_escu
Linux Node Privilege Escalation
splunk_escu
Linux NOPASSWD Entry In Sudoers File
splunk_escu
Linux Octave Privilege Escalation
splunk_escu
Linux OpenVPN Privilege Escalation
splunk_escu
Linux PHP Privilege Escalation
splunk_escu
Linux Possible Access To Sudoers File
splunk_escu
Linux Puppet Privilege Escalation
splunk_escu
Linux RPM Privilege Escalation
splunk_escu
Linux Ruby Privilege Escalation
splunk_escu
Linux Sqlite3 Privilege Escalation
splunk_escu
Linux Sudo OR Su Execution
splunk_escu
Linux Sudoers Tmp File Creation
splunk_escu
Linux Visudo Utility Execution
splunk_escu
Modification of Persistence Relevant Files Detected via Defend for Containers
elasticlow
Pod or Container Creation with Suspicious Command-Line
elasticmedium
Potential CVE-2025-32463 Sudo Chroot Execution Attempt
elastichigh
Potential Defense Evasion via Doas
elasticmedium
Potential Persistence via File Modification
elasticlow
Potential Privilege Escalation via Sudoers File Modification
elastichigh
Potential Sudo Hijacking
elasticmedium
Potential Sudo Privilege Escalation via CVE-2019-14287
elastichigh
Potential Sudo Token Manipulation via Process Injection
elasticmedium
Potential Suspicious File Edit
elasticlow
Sudo Command Enumeration Detected
elasticlow
Sudoers File Activity
elasticmedium
Suspicious Echo or Printf Execution Detected via Defend for Containers
elastichigh