Malicious Read Access to the Linux Shadow Password File (via process_creation)

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-02
Updated
2026-09-02

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects a shell or file utility reading /etc/shadow, the file holding Linux password hashes, which adversaries copy to crack credentials offline. OS credential access on Linux hosts supports the lateral movement and escalation documented in the Red Canary Threat Detection Report. Because /etc/shadow is normally accessed only by system authentication components, ad-hoc reads by cat, cp or editors are a strong credential-theft indicator.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.