Linux Persistence via /etc/sudoers.d File Creation or Modification

Alerts on file changes in /etc/sudoers.d/ that may indicate persistence via sudo privilege policy.

FreeReviewedSigma · Medium · v3
Product
linux
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-07-05
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags file creation or changes targeting the /etc/sudoers.d/ directory on Linux. Altering sudoers drop-in files can allow an attacker or administrator process to grant elevated permissions to specific users, supporting privilege escalation persistence. It relies on Linux file event telemetry that includes the target file path and the initiating process image path for excluding a known dpkg-generated artifact.

Related detections4 linkedT1548.003 — drag to rearrange
Suspicious Sudoers NOPASSWD Rule Written For Passwordless Privilege Escalation
Suspicious macOS Privilege Escalation Piping Password to sudo
Linux sudo CVE-2019-14287 exploit attempt via unusual USER strings
Linux Sudo Privilege Escalation Attempt Matching CVE-2019-14287 Command-Line Pattern
Linux Persistence via /etc/sudoers.d File Creation or Modification
Pivot detection · T1548.003 · 4 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.