Linux PAM TTY Auditing Change via auditd PATH Events

Alerts on auditd-observed edits to PAM system-auth/password-auth tied to TTY input auditing.

FreeUnreviewedSigmahighv1
title: Linux PAM TTY Auditing Change via auditd PATH Events
id: d6269d94-960f-4fb3-94b9-e952a59a72c8
status: test
description: This rule flags attempts to modify PAM configuration files related to system authentication by watching auditd PATH events for /etc/pam.d/system-auth and /etc/pam.d/password-auth. It also correlates the activity with TTY-related audit event types (TTY and USER_TTY), which is relevant because PAM TTY auditing can capture user keystrokes or terminal input. Attackers may use this to collect credentials or session input while remaining within normal authentication flows. Detection relies on auditd telemetry that records file path access alongside TTY audit event types.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1056.001/T1056.001.md
  - https://linux.die.net/man/8/pam_tty_audit
  - https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security_guide/sec-configuring_pam_for_auditing
  - https://access.redhat.com/articles/4409591#audit-record-types-2
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/lnx_auditd_keylogging_with_pam_d.yml
author: Pawel Mazur, Huntrule Team
date: 2021-05-24
modified: 2022-12-18
tags:
  - attack.collection
  - attack.credential-access
  - attack.t1003
  - attack.t1056.001
logsource:
  product: linux
  service: auditd
detection:
  selection_path_events:
    type: PATH
    name:
      - /etc/pam.d/system-auth
      - /etc/pam.d/password-auth
  selection_tty_events:
    type:
      - TTY
      - USER_TTY
  condition: 1 of selection_*
falsepositives:
  - Administrative work
level: high
license: DRL-1.1
related:
  - id: 49aae26c-450e-448b-911d-b3c13d178dfc
    type: derived

What it detects

This rule flags attempts to modify PAM configuration files related to system authentication by watching auditd PATH events for /etc/pam.d/system-auth and /etc/pam.d/password-auth. It also correlates the activity with TTY-related audit event types (TTY and USER_TTY), which is relevant because PAM TTY auditing can capture user keystrokes or terminal input. Attackers may use this to collect credentials or session input while remaining within normal authentication flows. Detection relies on auditd telemetry that records file path access alongside TTY audit event types.

Known false positives

  • Administrative work

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.