Linux: New user created with UID=0 or GID=0/10/27 indicating privileged group access

Alerts on Linux user creation events that assign privileged UID/GID values like root, wheel, or sudo.

FreeReviewedSigma · High · v3
Product
linux
Author
Pawel Mazur (SigmaHQ), DRL 1.1
Published
2022-12-21
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Linux user creation events that include identifiers consistent with privileged access, matching new-user log entries where UID=0 or GID=0, GID=10, or GID=27. Assigning root-level or sudo/wheel-equivalent group membership during account creation can enable immediate privilege escalation and persistence. It relies on Linux authentication logs capturing useradd-style messages containing "new user" plus UID/GID fields.

Related detections9 linkedT1136.001 — drag to rearrange
Suspicious Local Account Creation and Privileged Group Addition via Net.EXE (via process_creation)
Cisco AAA local account and remote authentication changes
Suspicious Local Account Creation via Net User in Pre-Ransomware Phase
Suspicious Hidden Local Account Creation via Net User by UAT-8099
Malicious Local Account Creation of Support or Whiteninja via net.exe
Malicious Dynamicweb Unauthenticated Administrator Creation via Setup Default.aspx (via webserver)
Suspicious Hidden Backdoor Account Creation Ending With Dollar Sign (via process_creation)
Malicious Cluster-Admin Role Binding Creation (via audit)
Malicious User Password Change Using Current Hash Password - ChangeNTLM - Mimikatz (via security)
Linux: New user created with UID=0 or GID=0/10/27 indicating privileged group access
Pivot detection · T1136.001 · 9 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.