Suspicious Sudoers NOPASSWD Rule Written For Passwordless Privilege Escalation

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-06-26
Updated
2026-08-28

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects writes to the sudoers configuration that grant passwordless all-command access which adversaries use to establish persistent privilege escalation on Linux hosts. Granting NOPASSWD ALL to a controlled account lets an attacker reliably regain root without supplying credentials.

Related detections4 linkedT1548.003 — drag to rearrange
Suspicious macOS Privilege Escalation Piping Password to sudo
Linux Persistence via /etc/sudoers.d File Creation or Modification
Linux sudo CVE-2019-14287 exploit attempt via unusual USER strings
Linux Sudo Privilege Escalation Attempt Matching CVE-2019-14287 Command-Line Pattern
Suspicious Sudoers NOPASSWD Rule Written For Passwordless Privilege Escalation
Pivot detection · T1548.003 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.