Linux Password Policy Discovery via chage and passwd Commands

Identifies Linux password policy discovery by running chage/waswo with status arguments and reading common password policy files.

FreeReviewedSigma · Low · v3
Product
linux
Service
auditd
Author
Ömer Günal, oscd.community, Pawel Mazur (SigmaHQ), DRL 1.1
Published
2020-10-08
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies attempts to discover Linux password policy information by executing chage or passwd with options that reveal account and password status. Attackers use this knowledge to tailor password-guessing or account-manipulation attempts to local policy constraints. Detection relies on auditd process execution telemetry (EXECVE) for the specific binaries and relevant configuration file names.

Related detections6 linkedT1201 — drag to rearrange
Suspicious Secedit Security Policy Export for Reconnaissance (via process_creation)
Windows Security Event 4661 Password Policy Enumeration via ReadPasswordParameters
PowerShell Password Policy Discovery via Get-AdDefaultDomainPasswordPolicy (Windows)
Windows process creation: CrackMapExec execution via characteristic command-line flags
Cisco AAA discovery via show/dir commands
Windows Process Creation: Execution of Net.exe or Net1.exe
Linux Password Policy Discovery via chage and passwd Commands
Pivot detection · T1201 · 6 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.