Sudo and Sudo Caching
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges. Within Linux and MacOS systems, sudo (sometimes referred to as "superuser do") allows users to perform commands from terminals with elevated privileges and to control who can perform these commands on the system. The <code>sudo</code> command "allows a system administrator to delegate authority to give certa...
BY SOURCE
PROCEDURES (14)
Auto-extracted: 19 detections for general monitoring
Auto-extracted: 7 detections for persist
Auto-extracted: 4 detections for process creation monitoring
Auto-extracted: 3 detections for persist
Auto-extracted: 2 detections for persist
Auto-extracted: 2 detections for script execution monitoring
Auto-extracted: 2 detections for suspicious
Auto-extracted: 2 detections for parent process
Auto-extracted: 2 detections for container
Auto-extracted: 2 detections for file monitoring
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for exfiltrat
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for suspicious