Linux PAM TTY Audit Enabling via /etc/pam.d Modification

Alerts on auditd-observed edits to PAM system-auth/password-auth tied to TTY input auditing.

FreeReviewedSigma · High · v3
Product
linux
Service
auditd
Author
Pawel Mazur (SigmaHQ), DRL 1.1
Published
2021-05-24
Updated
2026-07-31

ATT&CK techniques

Cred Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Linux auditd PATH and TTY-related events indicating access to PAM configuration files used for system authentication, specifically /etc/pam.d/system-auth and /etc/pam.d/password-auth. Enabling TTY input auditing can support credential collection or keylogging-like behaviors by recording interactive terminal input. The detection relies on auditd telemetry capturing file path activity along with TTY/USER_TTY indicators.

Related detections9 linkedT1056.001 — drag to rearrange
Suspicious Keylog and Screenshot Files in windows-cache Directory (OtterCookie)
Suspicious WezRat Keylog File in Temp Directory
Suspicious Larva-24009 Keylogger Log Staging in OneDrive Path (via file_event)
Malicious Wdigest Authentication Enabled - Reg via Command (via process_creation)
Malicious Diskshadow Command Abuse to Expose VSS Backup (via process_creation)
Malicious IIS Application Pool Credential Dumping (via process_creation)
Suspicious Kimsuky AlphaSeed Artifacts in edge Hidden Directory (via file_event)
Malicious Wdigest Authentication Enabled - Registry (via registry_set)
In-Memory Remcos RAT Keylog Store Created Under ProgramData rema (via file_event)
Linux PAM TTY Audit Enabling via /etc/pam.d Modification
Pivot detection · T1056.001 · 9 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.