Linux PAM TTY Audit Enabling via /etc/pam.d Modification

Alerts on auditd-observed edits to PAM system-auth/password-auth tied to TTY input auditing.

FreeReviewedSigma · High · v3
Product
linux
Service
auditd
Author
Pawel Mazur (SigmaHQ), DRL 1.1
Published
2021-05-24
Updated
2026-07-31
title: Linux PAM TTY Audit Enabling via /etc/pam.d Modification
id: d6269d94-960f-4fb3-94b9-e952a59a72c8
status: test
description: This rule flags Linux auditd PATH and TTY-related events indicating access to PAM configuration files used for system authentication, specifically /etc/pam.d/system-auth and /etc/pam.d/password-auth. Enabling TTY input auditing can support credential collection or keylogging-like behaviors by recording interactive terminal input. The detection relies on auditd telemetry capturing file path activity along with TTY/USER_TTY indicators.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1056.001/T1056.001.md
  - https://linux.die.net/man/8/pam_tty_audit
  - https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security_guide/sec-configuring_pam_for_auditing
  - https://access.redhat.com/articles/4409591#audit-record-types-2
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/lnx_auditd_keylogging_with_pam_d.yml
author: Pawel Mazur, Huntrule Team
date: 2021-05-24
modified: 2022-12-18
tags:
  - attack.collection
  - attack.credential-access
  - attack.t1003
  - attack.t1056.001
logsource:
  product: linux
  service: auditd
detection:
  selection_path_events:
    type: PATH
    name:
      - /etc/pam.d/system-auth
      - /etc/pam.d/password-auth
  selection_tty_events:
    type:
      - TTY
      - USER_TTY
  condition: 1 of selection_*
falsepositives:
  - Administrative work
level: high
license: DRL-1.1
related:
  - id: 49aae26c-450e-448b-911d-b3c13d178dfc
    type: derived