Abuse Elevation Control Mechanism: Sudo and Sudo Caching T1548.003
Tactic: Privilege Escalation
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges.
Events covered
2 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon-for-Linux | Event ID 1 | Process Create |
| Sysmon-for-Linux | Event ID 11 | File created |
Authoring guide
Patterns shared across the 58 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (38 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (563 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (106 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 5 rules
- macOS Multiple Failed Sudo Attempts
- macOS Sudo Privilege Escalation Attempts
- Persistence Via Sudoers.d Files
- Sudo Privilege Escalation CVE-2019-14287
- Sudo Privilege Escalation CVE-2019-14287 - Builtin
Elastic 17 rules
- Deprecated - Sudo Heap-Based Buffer Overflow Attempt
- Modification of Persistence Relevant Files Detected via Defend for Containers
- Pod or Container Creation with Suspicious Command-Line
- Potential CVE-2025-32463 Sudo Chroot Execution Attempt
- Potential Defense Evasion via Doas
- Potential Persistence via File Modification
- Potential Privilege Escalation via Sudoers File Modification
- Potential Privilege Escalation via SUID/SGID
- Potential Sudo Hijacking
- Potential Sudo Privilege Escalation via CVE-2019-14287
- Potential Sudo Token Manipulation via Process Injection
- Potential Suspicious File Edit
- Sudo Command Enumeration Detected
- Sudoers File Activity
- Suspicious Echo or Printf Execution Detected via Defend for Containers
- Suspicious SUID Binary Execution
- Suspicious SUID Binary Execution (Auditd Sequence)
Splunk 35 rules
- Linux APT Privilege Escalation
- Linux Auditd Doas Conf File Creation
- Linux Auditd Doas Tool Execution
- Linux Auditd Nopasswd Entry In Sudoers File
- Linux Auditd Possible Access To Sudoers File
- Linux Auditd Sudo Or Su Execution
- Linux AWK Privilege Escalation
- Linux Busybox Privilege Escalation
- Linux c89 Privilege Escalation
- Linux c99 Privilege Escalation
- Linux Composer Privilege Escalation
- Linux Cpulimit Privilege Escalation
- Linux Csvtool Privilege Escalation
- Linux Doas Conf File Creation
- Linux Doas Tool Execution
- Linux Emacs Privilege Escalation
- Linux Find Privilege Escalation
- Linux GDB Privilege Escalation
- Linux Gem Privilege Escalation
- Linux GNU Awk Privilege Escalation
- Linux Make Privilege Escalation
- Linux MySQL Privilege Escalation
- Linux Node Privilege Escalation
- Linux NOPASSWD Entry In Sudoers File
- Linux Octave Privilege Escalation
- Linux OpenVPN Privilege Escalation
- Linux PHP Privilege Escalation
- Linux Possible Access To Sudoers File
- Linux Puppet Privilege Escalation
- Linux RPM Privilege Escalation
- Linux Ruby Privilege Escalation
- Linux Sqlite3 Privilege Escalation
- Linux Sudo OR Su Execution
- Linux Sudoers Tmp File Creation
- Linux Visudo Utility Execution