Linux PAM TTY Auditing Change via auditd PATH Events
Alerts on auditd-observed edits to PAM system-auth/password-auth tied to TTY input auditing.
FreeUnreviewedSigmahighv1
linux-pam-tty-auditing-change-via-auditd-path-events-49aae26c
title: Linux PAM TTY Auditing Change via auditd PATH Events
id: d6269d94-960f-4fb3-94b9-e952a59a72c8
status: test
description: This rule flags attempts to modify PAM configuration files related to system authentication by watching auditd PATH events for /etc/pam.d/system-auth and /etc/pam.d/password-auth. It also correlates the activity with TTY-related audit event types (TTY and USER_TTY), which is relevant because PAM TTY auditing can capture user keystrokes or terminal input. Attackers may use this to collect credentials or session input while remaining within normal authentication flows. Detection relies on auditd telemetry that records file path access alongside TTY audit event types.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1056.001/T1056.001.md
- https://linux.die.net/man/8/pam_tty_audit
- https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security_guide/sec-configuring_pam_for_auditing
- https://access.redhat.com/articles/4409591#audit-record-types-2
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/lnx_auditd_keylogging_with_pam_d.yml
author: Pawel Mazur, Huntrule Team
date: 2021-05-24
modified: 2022-12-18
tags:
- attack.collection
- attack.credential-access
- attack.t1003
- attack.t1056.001
logsource:
product: linux
service: auditd
detection:
selection_path_events:
type: PATH
name:
- /etc/pam.d/system-auth
- /etc/pam.d/password-auth
selection_tty_events:
type:
- TTY
- USER_TTY
condition: 1 of selection_*
falsepositives:
- Administrative work
level: high
license: DRL-1.1
related:
- id: 49aae26c-450e-448b-911d-b3c13d178dfc
type: derived
What it detects
This rule flags attempts to modify PAM configuration files related to system authentication by watching auditd PATH events for /etc/pam.d/system-auth and /etc/pam.d/password-auth. It also correlates the activity with TTY-related audit event types (TTY and USER_TTY), which is relevant because PAM TTY auditing can capture user keystrokes or terminal input. Attackers may use this to collect credentials or session input while remaining within normal authentication flows. Detection relies on auditd telemetry that records file path access alongside TTY audit event types.
Known false positives
- Administrative work
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.