Modify Authentication Process: Pluggable Authentication Modules T1556.003

Tactics: Defense Impairment, Persistence, Credential Access

Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts. PAM is a modular system of configuration files, libraries, and executable files which guide authentication for many services. The most common authentication module is pam_unix.so, which retrieves, sets, and verifies account authentication information in /etc/passwd and /etc/shadow.

Authoring guide

These 6 rules share fields, values, and exclusions.

Fields filtered most (17 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
host.os.type5eq 5
EventType4eq 3, in 1exec, ProcessRollup2, authenticated, creation, exec_event
event.type3eq 3start, change, creation
Image2is_not_null 1, starts_with 1./, /bin/, /boot/
process.args2wildcard 2/bin/bash, /bin/dash, /bin/lua*, https://github.com/linux-pam/linux-pam/releases/download/...
process_name2in 2, starts_with 1., curl, ssh, sshd, wget
TargetFilename1eq 1, starts_with 1/etc/pam.conf, /etc/pam.d/, /etc/security/pam_
action1eq 1user_login_failed
auditd.data.grantors1is_not_null 1
event.category1eq 1authentication
event.outcome1eq 1success
event_type1eq 1login
file.extension1eq 1, is_null 1so
file.name1wildcard 1pam_*.so
parent_process_name1in 1ssh, sshd

Top indicator values (95 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
21087
EventTypeeq
authenticated
1
EventTypeeq
creation
158
EventTypeeq
exec
1579
EventTypeeq
session_id_change
12
EventTypein
ProcessRollup2
1118
EventTypein
exec
1206
EventTypein
exec_event
1150
Imagestarts_with
./
126
Imagestarts_with
/bin/
13
Imagestarts_with
/boot/
128
Imagestarts_with
/dev/shm/
153
Imagestarts_with
/lib/
1
Imagestarts_with
/lib64/
1
Imagestarts_with
/lost+found/
113
Imagestarts_with
/media/
15
Imagestarts_with
/opt/
12
Imagestarts_with
/proc/
113
Imagestarts_with
/run/
120
Imagestarts_with
/sbin/
12
Imagestarts_with
/sys/
114
Imagestarts_with
/tmp/
158
Imagestarts_with
/usr/bin/
13
Imagestarts_with
/usr/lib/
1
Imagestarts_with
/usr/lib64/
1
Imagestarts_with
/usr/sbin/
12
Imagestarts_with
/var/backups/
14
Imagestarts_with
/var/lib/
14
Imagestarts_with
/var/log/
17
Imagestarts_with
/var/mail/
114

Exclusions (132 distinct)

These values appear most often in top-level exclusions.

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Elastic 5 rules

Kusto 1 rule