Linux auth logs: pkexec and XAUTHORITY strings indicating PwnKit (CVE-2021-4034) attempt

Alerts on Linux auth log entries with pkexec and PwnKit-related environment/session keywords consistent with CVE-2021-4034 attempts.

FreeReviewedSigma · High · v5
Product
linux
Service
auth
Author
Sreeman (SigmaHQ), DRL 1.1
Published
2022-01-26
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Linux authentication log entries containing specific pkexec-related and XAUTHORITY-related strings that may indicate a PwnKit (CVE-2021-4034) local privilege escalation attempt. Attackers can use pkexec with manipulated environment variables to escalate privileges, so these distinctive log patterns are valuable for early triage. The detection relies on keyword matches in auth log text, including a suspicious XAUTHORITY message and a root/TTY pattern.

Related detections3 linkedT1548.001 — drag to rearrange
Possible CopyFail Root Exploitation via Python Spawning SUID Shell (via process_creation)
Suspicious User and Network Namespace Creation via unshare on Linux
Linux process activity: chown root and setuid/setgid chmod flags
Linux auth logs: pkexec and XAUTHORITY strings indicating PwnKit (CVE-2021-4034) attempt
Pivot detection · T1548.001 · 3 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.