Linux PAM TTY Audit Enabling via /etc/pam.d Modification
Alerts on auditd-observed edits to PAM system-auth/password-auth tied to TTY input auditing.
- Product
- linux
- Service
- auditd
- Author
- Pawel Mazur (SigmaHQ), DRL 1.1
- Published
- 2021-05-24
- Updated
- 2026-07-31
ATT&CK techniques
Cred Access → CollectionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Linux auditd PATH and TTY-related events indicating access to PAM configuration files used for system authentication, specifically /etc/pam.d/system-auth and /etc/pam.d/password-auth. Enabling TTY input auditing can support credential collection or keylogging-like behaviors by recording interactive terminal input. The detection relies on auditd telemetry capturing file path activity along with TTY/USER_TTY indicators.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1056.001/T1056.001.md
- linux.die.nethttps://linux.die.net/man/8/pam_tty_audit
- access.redhat.comhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security_guide/sec-configuring_pam_for_auditing
- access.redhat.comhttps://access.redhat.com/articles/4409591#audit-record-types-2
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/lnx_auditd_keylogging_with_pam_d.yml
Changelog
v3- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux PAM TTY Audit Enabling via /etc/pam.d Modification
id: d6269d94-960f-4fb3-94b9-e952a59a72c8
status: test
description: This rule flags Linux auditd PATH and TTY-related events indicating access to PAM configuration files used for system authentication, specifically /etc/pam.d/system-auth and /etc/pam.d/password-auth. Enabling TTY input auditing can support credential collection or keylogging-like behaviors by recording interactive terminal input. The detection relies on auditd telemetry capturing file path activity along with TTY/USER_TTY indicators.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1056.001/T1056.001.md
- https://linux.die.net/man/8/pam_tty_audit
- https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security_guide/sec-configuring_pam_for_auditing
- https://access.redhat.com/articles/4409591#audit-record-types-2
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/lnx_auditd_keylogging_with_pam_d.yml
author: Pawel Mazur, Huntrule Team
date: 2021-05-24
modified: 2022-12-18
tags:
- attack.collection
- attack.credential-access
- attack.t1003
- attack.t1056.001
logsource:
product: linux
service: auditd
detection:
selection_path_events:
type: PATH
name:
- /etc/pam.d/system-auth
- /etc/pam.d/password-auth
selection_tty_events:
type:
- TTY
- USER_TTY
condition: 1 of selection_*
falsepositives:
- Administrative work
level: high
license: DRL-1.1
related:
- id: 49aae26c-450e-448b-911d-b3c13d178dfc
type: derived