Modify Authentication Process: Pluggable Authentication Modules T1556.003
Tactics: Defense Impairment, Persistence, Credential Access
Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts. PAM is a modular system of configuration files, libraries, and executable files which guide authentication for many services. The most common authentication module is pam_unix.so, which retrieves, sets, and verifies account authentication information in /etc/passwd and /etc/shadow.
Authoring guide
These 6 rules share fields, values, and exclusions.
Fields filtered most (17 distinct)
These fields appear most often in rule filters.
Top indicator values (95 distinct)
These values appear most often in rule predicates.
Exclusions (132 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Elastic 5 rules
- Authentication via Unusual PAM Grantor
- Pluggable Authentication Module (PAM) Creation in Unusual Directory
- Pluggable Authentication Module (PAM) Source Download
- Pluggable Authentication Module or Configuration Creation
- Potential Backdoor Execution Through PAM_EXEC