Linux Local Account Enumeration via lastlog, /etc/* file reads, id, and lsof -u
Flags Linux process activity consistent with enumerating local system accounts using /etc account data and related tools.
- Product
- linux
- Category
- process_creation
- Author
- Alejandro Ortuno, oscd.community, CheraghiMilad (SigmaHQ), DRL 1.1
- Published
- 2020-10-08
- Updated
- 2026-07-31
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies Linux process activity indicative of local account enumeration, such as invoking utilities like lastlog, cat/vi-like tools, id, and lsof with user-focused options. It matters because discovering which local accounts exist can support later targeting and privilege-related actions. The detection relies on process creation telemetry, matching image paths and command-line content that reference common account databases and related files like /etc/passwd and /etc/shadow.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1087.001/T1087.001.md
- my.f5.comhttps://my.f5.com/manage/s/article/K589
- man.freebsd.orghttps://man.freebsd.org/cgi/man.cgi?pwd_mkdb
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_local_account.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux Local Account Enumeration via lastlog, /etc/* file reads, id, and lsof -u
id: 519a106e-7363-4575-a973-694ac9f37220
status: test
description: This rule identifies Linux process activity indicative of local account enumeration, such as invoking utilities like lastlog, cat/vi-like tools, id, and lsof with user-focused options. It matters because discovering which local accounts exist can support later targeting and privilege-related actions. The detection relies on process creation telemetry, matching image paths and command-line content that reference common account databases and related files like /etc/passwd and /etc/shadow.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1087.001/T1087.001.md
- https://my.f5.com/manage/s/article/K589
- https://man.freebsd.org/cgi/man.cgi?pwd_mkdb
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_local_account.yml
author: Alejandro Ortuno, oscd.community, CheraghiMilad, Huntrule Team
date: 2020-10-08
modified: 2024-12-10
tags:
- attack.discovery
- attack.t1087.001
logsource:
category: process_creation
product: linux
detection:
selection_1:
Image|endswith: /lastlog
selection_2:
CommandLine|contains: "'x:0:'"
selection_3:
Image|endswith:
- /cat
- /ed
- /head
- /more
- /nano
- /tail
- /vi
- /vim
- /less
- /emacs
- /sqlite3
- /makemap
CommandLine|contains:
- /etc/passwd
- /etc/shadow
- /etc/sudoers
- /etc/spwd.db
- /etc/pwd.db
- /etc/master.passwd
selection_4:
Image|endswith: /id
selection_5:
Image|endswith: /lsof
CommandLine|contains: -u
condition: 1 of selection*
falsepositives:
- Legitimate administration activities
level: low
license: DRL-1.1
related:
- id: b45e3d6f-42c6-47d8-a478-df6bd6cf534c
type: derived